mirror of
https://github.com/mthcht/ThreatHunting-Keywords
synced 2026-06-08 16:12:28 +00:00
755048bf5e
very few additions and some corrections
289 KiB
289 KiB
| 1 | keyword | metadata_keyword_regex | metadata_keyword_type | metadata_tool | metadata_description | metadata_tool_techniques | metadata_tool_tactics | metadata_malwares_name | metadata_groups_name | metadata_category | metadata_link | metadata_enable_endpoint_detection | metadata_enable_proxy_detection | metadata_tags | metadata_comment | metadata_severity_score | metadata_popularity_score | metadata_github_stars | metadata_github_forks | metadata_github_updated_at | metadata_github_created_at | metadata_entry_id |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2 | *- {phish_sub: * | .{0,1000}\-\s\{phish_sub\:\s.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/Evilginx2-Phishlets | 1 | 0 | #content | N/A | 10 | 7 | 670 | 263 | 2025-02-06T02:46:16Z | 2020-05-13T05:58:43Z | 132 |
| 3 | * 365-Stealer * | .{0,1000}\s365\-Stealer\s.{0,1000} | offensive_tool_keyword | 365-Stealer | 365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack | T1111 - T1566.001 - T1078.004 | TA0004 - TA0001 - TA0040 | N/A | N/A | Phishing | https://github.com/AlteredSecurity/365-Stealer | 1 | 0 | N/A | N/A | 10 | 5 | 488 | 89 | 2024-06-08T21:03:50Z | 2020-09-20T18:22:36Z | 160 |
| 4 | * camhacker * | .{0,1000}\scamhacker\s.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 540 |
| 5 | * camhacker:/CamHacker* | .{0,1000}\scamhacker\:\/CamHacker.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 541 | ||||
| 6 | * --CollectLinks --apitoken * --outfile * | .{0,1000}\s\-\-CollectLinks\s\-\-apitoken\s.{0,1000}\s\-\-outfile\s.{0,1000} | offensive_tool_keyword | clickjack | automate abuse of clickonce applications | T1210 - T1204 - T1071.001 | TA0001 - TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/trustedsec/The_Shelf | 1 | 0 | N/A | N/A | 10 | 3 | 247 | 14 | 2024-11-25T19:33:34Z | 2024-05-22T14:31:52Z | 656 |
| 7 | * --custom-steal | .{0,1000}\s\-\-custom\-steal | offensive_tool_keyword | 365-Stealer | 365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack | T1111 - T1566.001 - T1078.004 | TA0004 - TA0001 - TA0040 | N/A | N/A | Phishing | https://github.com/AlteredSecurity/365-Stealer | 1 | 0 | N/A | N/A | 10 | 5 | 488 | 89 | 2024-06-08T21:03:50Z | 2020-09-20T18:22:36Z | 754 |
| 8 | * --custom-steal listusers* | .{0,1000}\s\-\-custom\-steal\slistusers.{0,1000} | offensive_tool_keyword | 365-Stealer | 365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack | T1111 - T1566.001 - T1078.004 | TA0004 - TA0001 - TA0040 | N/A | N/A | Phishing | https://github.com/AlteredSecurity/365-Stealer | 1 | 0 | N/A | N/A | 10 | 5 | 488 | 89 | 2024-06-08T21:03:50Z | 2020-09-20T18:22:36Z | 755 |
| 9 | * --custom-steal onedrive* | .{0,1000}\s\-\-custom\-steal\sonedrive.{0,1000} | offensive_tool_keyword | 365-Stealer | 365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack | T1111 - T1566.001 - T1078.004 | TA0004 - TA0001 - TA0040 | N/A | N/A | Phishing | https://github.com/AlteredSecurity/365-Stealer | 1 | 0 | N/A | N/A | 10 | 5 | 488 | 89 | 2024-06-08T21:03:50Z | 2020-09-20T18:22:36Z | 756 |
| 10 | * --custom-steal onenote* | .{0,1000}\s\-\-custom\-steal\sonenote.{0,1000} | offensive_tool_keyword | 365-Stealer | 365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack | T1111 - T1566.001 - T1078.004 | TA0004 - TA0001 - TA0040 | N/A | N/A | Phishing | https://github.com/AlteredSecurity/365-Stealer | 1 | 0 | N/A | N/A | 10 | 5 | 488 | 89 | 2024-06-08T21:03:50Z | 2020-09-20T18:22:36Z | 757 |
| 11 | * --custom-steal outlook* | .{0,1000}\s\-\-custom\-steal\soutlook.{0,1000} | offensive_tool_keyword | 365-Stealer | 365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack | T1111 - T1566.001 - T1078.004 | TA0004 - TA0001 - TA0040 | N/A | N/A | Phishing | https://github.com/AlteredSecurity/365-Stealer | 1 | 0 | N/A | N/A | 10 | 5 | 488 | 89 | 2024-06-08T21:03:50Z | 2020-09-20T18:22:36Z | 758 |
| 12 | * domainhunter * | .{0,1000}\sdomainhunter\s.{0,1000} | offensive_tool_keyword | domainhunter | Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names | T1583.002 - T1568.002 | TA0011 - TA0009 | N/A | N/A | Phishing | https://github.com/threatexpress/domainhunter | 1 | 0 | N/A | N/A | N/A | 10 | 1587 | 292 | 2024-06-06T21:01:21Z | 2017-03-01T11:16:26Z | 912 |
| 13 | * evilginx* | .{0,1000}\sevilginx.{0,1000} | offensive_tool_keyword | gophish | Combination of evilginx2 and GoPhish | T1565-002 - T1565-003 - T1565-012 - T1110 - T1056-001 - T1113 | TA0002 - TA0003 | N/A | Black Basta | Phishing | https://github.com/fin3ss3g0d/evilgophish | 1 | 0 | N/A | N/A | 10 | 10 | 1762 | 340 | 2024-06-15T17:48:11Z | 2022-09-07T02:47:43Z | 1087 |
| 14 | * EvilnoVNC by @JoelGMSec* | .{0,1000}\sEvilnoVNC\sby\s\@JoelGMSec.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/ms101/EvilKnievelnoVNC | 1 | 0 | #linux #content | N/A | 9 | 1 | 44 | 8 | 2025-03-08T19:34:41Z | 2024-04-13T22:05:04Z | 1088 |
| 15 | * EvilnoVNC* | .{0,1000}\sEvilnoVNC.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 0 | N/A | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 1089 |
| 16 | * evil-proxy* | .{0,1000}\sevil\-proxy.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 1090 |
| 17 | * evil-proxy.rb* | .{0,1000}\sevil\-proxy\.rb.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 1091 |
| 18 | * ExtensionSpoof.exe* | .{0,1000}\sExtensionSpoof\.exe.{0,1000} | offensive_tool_keyword | ExtensionSpoofer | Spoof file icons and extensions in Windows | T1036 - T1027.005 - T1218 | TA0005 - TA0040 | N/A | N/A | Phishing | https://github.com/henriksb/ExtensionSpoofer | 1 | 0 | N/A | N/A | 9 | 2 | 179 | 65 | 2024-12-12T18:05:28Z | 2017-11-11T16:02:17Z | 1140 |
| 19 | * --fuzzers addition* | .{0,1000}\s\-\-fuzzers\saddition.{0,1000} | offensive_tool_keyword | dnstwist | See what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence. | T1560 - T1565 - T1566 - T1568 - T1569 | TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/elceef/dnstwist | 1 | 0 | N/A | N/A | 3 | 10 | 5113 | 801 | 2025-04-15T18:41:47Z | 2015-06-11T12:24:17Z | 1263 |
| 20 | * --fuzzers bitsquatting* | .{0,1000}\s\-\-fuzzers\sbitsquatting.{0,1000} | offensive_tool_keyword | dnstwist | See what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence. | T1560 - T1565 - T1566 - T1568 - T1569 | TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/elceef/dnstwist | 1 | 0 | N/A | N/A | 3 | 10 | 5113 | 801 | 2025-04-15T18:41:47Z | 2015-06-11T12:24:17Z | 1264 |
| 21 | * --fuzzers cyrillic* | .{0,1000}\s\-\-fuzzers\scyrillic.{0,1000} | offensive_tool_keyword | dnstwist | See what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence. | T1560 - T1565 - T1566 - T1568 - T1569 | TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/elceef/dnstwist | 1 | 0 | N/A | N/A | 3 | 10 | 5113 | 801 | 2025-04-15T18:41:47Z | 2015-06-11T12:24:17Z | 1265 |
| 22 | * --fuzzers dictionary* | .{0,1000}\s\-\-fuzzers\sdictionary.{0,1000} | offensive_tool_keyword | dnstwist | See what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence. | T1560 - T1565 - T1566 - T1568 - T1569 | TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/elceef/dnstwist | 1 | 0 | N/A | N/A | 3 | 10 | 5113 | 801 | 2025-04-15T18:41:47Z | 2015-06-11T12:24:17Z | 1266 |
| 23 | * --fuzzers homoglyph* | .{0,1000}\s\-\-fuzzers\shomoglyph.{0,1000} | offensive_tool_keyword | dnstwist | See what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence. | T1560 - T1565 - T1566 - T1568 - T1569 | TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/elceef/dnstwist | 1 | 0 | N/A | N/A | 3 | 10 | 5113 | 801 | 2025-04-15T18:41:47Z | 2015-06-11T12:24:17Z | 1267 |
| 24 | * --fuzzers hyphenation* | .{0,1000}\s\-\-fuzzers\shyphenation.{0,1000} | offensive_tool_keyword | dnstwist | See what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence. | T1560 - T1565 - T1566 - T1568 - T1569 | TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/elceef/dnstwist | 1 | 0 | N/A | N/A | 3 | 10 | 5113 | 801 | 2025-04-15T18:41:47Z | 2015-06-11T12:24:17Z | 1268 |
| 25 | * --fuzzers insertion* | .{0,1000}\s\-\-fuzzers\sinsertion.{0,1000} | offensive_tool_keyword | dnstwist | See what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence. | T1560 - T1565 - T1566 - T1568 - T1569 | TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/elceef/dnstwist | 1 | 0 | N/A | N/A | 3 | 10 | 5113 | 801 | 2025-04-15T18:41:47Z | 2015-06-11T12:24:17Z | 1269 |
| 26 | * --fuzzers omission* | .{0,1000}\s\-\-fuzzers\somission.{0,1000} | offensive_tool_keyword | dnstwist | See what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence. | T1560 - T1565 - T1566 - T1568 - T1569 | TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/elceef/dnstwist | 1 | 0 | N/A | N/A | 3 | 10 | 5113 | 801 | 2025-04-15T18:41:47Z | 2015-06-11T12:24:17Z | 1270 |
| 27 | * --fuzzers repetition* | .{0,1000}\s\-\-fuzzers\srepetition.{0,1000} | offensive_tool_keyword | dnstwist | See what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence. | T1560 - T1565 - T1566 - T1568 - T1569 | TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/elceef/dnstwist | 1 | 0 | N/A | N/A | 3 | 10 | 5113 | 801 | 2025-04-15T18:41:47Z | 2015-06-11T12:24:17Z | 1271 |
| 28 | * --fuzzers replacement* | .{0,1000}\s\-\-fuzzers\sreplacement.{0,1000} | offensive_tool_keyword | dnstwist | See what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence. | T1560 - T1565 - T1566 - T1568 - T1569 | TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/elceef/dnstwist | 1 | 0 | N/A | N/A | 3 | 10 | 5113 | 801 | 2025-04-15T18:41:47Z | 2015-06-11T12:24:17Z | 1272 |
| 29 | * --fuzzers subdomain* | .{0,1000}\s\-\-fuzzers\ssubdomain.{0,1000} | offensive_tool_keyword | dnstwist | See what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence. | T1560 - T1565 - T1566 - T1568 - T1569 | TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/elceef/dnstwist | 1 | 0 | N/A | N/A | 3 | 10 | 5113 | 801 | 2025-04-15T18:41:47Z | 2015-06-11T12:24:17Z | 1273 |
| 30 | * --fuzzers transposition* | .{0,1000}\s\-\-fuzzers\stransposition.{0,1000} | offensive_tool_keyword | dnstwist | See what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence. | T1560 - T1565 - T1566 - T1568 - T1569 | TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/elceef/dnstwist | 1 | 0 | N/A | N/A | 3 | 10 | 5113 | 801 | 2025-04-15T18:41:47Z | 2015-06-11T12:24:17Z | 1274 |
| 31 | * --fuzzers vowel-swap* | .{0,1000}\s\-\-fuzzers\svowel\-swap.{0,1000} | offensive_tool_keyword | dnstwist | See what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence. | T1560 - T1565 - T1566 - T1568 - T1569 | TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/elceef/dnstwist | 1 | 0 | N/A | N/A | 3 | 10 | 5113 | 801 | 2025-04-15T18:41:47Z | 2015-06-11T12:24:17Z | 1275 |
| 32 | * --greeting * --personalize *--securelink* | .{0,1000}\s\-\-greeting\s.{0,1000}\s\-\-personalize\s.{0,1000}\-\-securelink.{0,1000} | offensive_tool_keyword | teamsphisher | Send phishing messages and attachments to Microsoft Teams users | T1566.001 - T1566.002 - T1204.001 | TA0001 - TA0005 | N/A | Black Basta | Phishing | https://github.com/Octoberfest7/TeamsPhisher | 1 | 0 | N/A | N/A | N/A | 10 | 1073 | 138 | 2024-06-19T21:41:55Z | 2023-07-03T02:19:47Z | 1384 |
| 33 | * --Inject --stub *.dll* --app * | .{0,1000}\s\-\-Inject\s\-\-stub\s.{0,1000}\.dll.{0,1000}\s\-\-app\s.{0,1000} | offensive_tool_keyword | clickjack | automate abuse of clickonce applications | T1210 - T1204 - T1071.001 | TA0001 - TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/trustedsec/The_Shelf | 1 | 0 | N/A | N/A | 10 | 3 | 247 | 14 | 2024-11-25T19:33:34Z | 2024-05-22T14:31:52Z | 1662 |
| 34 | * install evil-proxy* | .{0,1000}\sinstall\sevil\-proxy.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 1686 |
| 35 | * --keyword * --check --ocr * --alexa* | .{0,1000}\s\-\-keyword\s.{0,1000}\s\-\-check\s\-\-ocr\s.{0,1000}\s\-\-alexa.{0,1000} | offensive_tool_keyword | domainhunter | Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names | T1583.002 - T1568.002 | TA0011 - TA0009 | N/A | N/A | Phishing | https://github.com/threatexpress/domainhunter | 1 | 0 | N/A | N/A | N/A | 10 | 1587 | 292 | 2024-06-06T21:01:21Z | 2017-03-01T11:16:26Z | 1882 |
| 36 | * pastehakk.sh* | .{0,1000}\spastehakk\.sh.{0,1000} | offensive_tool_keyword | pastehakk | perform clipboard poisoning or paste jacking attack | T1115 | T0001 - T0002 - T0005 | N/A | N/A | Phishing | https://github.com/3xploitGuy/pastehakk | 1 | 0 | #linux | N/A | 7 | 1 | 56 | 10 | 2020-06-22T01:17:53Z | 2020-06-17T19:32:24Z | 2539 |
| 37 | * Redirect Url After Stealing ==> * | .{0,1000}\sRedirect\sUrl\sAfter\sStealing\s\=\=\>\s.{0,1000} | offensive_tool_keyword | 365-Stealer | 365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack | T1111 - T1566.001 - T1078.004 | TA0004 - TA0001 - TA0040 | N/A | N/A | Phishing | https://github.com/AlteredSecurity/365-Stealer | 1 | 0 | N/A | N/A | 10 | 5 | 488 | 89 | 2024-06-08T21:03:50Z | 2020-09-20T18:22:36Z | 2811 |
| 38 | * saycheese.sh* | .{0,1000}\ssaycheese\.sh.{0,1000} | offensive_tool_keyword | saycheese | Grab target's webcam shots by link | T1213 - T1071 - T1102 - T1123 - T1185 - T1200 | TA0001 - TA0005 - TA0009 - TA0011 | N/A | N/A | Phishing | https://github.com/hangetzzu/saycheese | 1 | 0 | N/A | N/A | 9 | 10 | 1175 | 962 | 2024-06-18T23:39:41Z | 2019-04-29T04:07:00Z | 2983 |
| 39 | * smuggler.py* | .{0,1000}\ssmuggler\.py.{0,1000} | offensive_tool_keyword | smuggler.py | HTML Smuggling Generator | T1564.001 - T1027 - T1566 | TA0005 | N/A | N/A | Phishing | https://github.com/infosecn1nja/red-team-scripts/blob/main/smuggler.py | 1 | 0 | N/A | N/A | 9 | 3 | 299 | 55 | 2024-08-08T06:11:06Z | 2023-01-15T22:37:34Z | 3269 |
| 40 | * termux-chroot */cloudflared* | .{0,1000}\stermux\-chroot\s.{0,1000}\/cloudflared.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 3502 | ||||
| 41 | * tricky.ps1* | .{0,1000}\stricky\.ps1.{0,1000} | offensive_tool_keyword | tricky.lnk | VBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and execute | T1027 - T1036 - T1218.010 | TA0002 - TA0003 - TA0008 | N/A | N/A | Phishing | https://github.com/xillwillx/tricky.lnk | 1 | 0 | N/A | N/A | N/A | 2 | 114 | 33 | 2020-12-19T23:42:10Z | 2016-10-26T21:25:06Z | 3555 |
| 42 | * tricky.vbs* | .{0,1000}\stricky\.vbs.{0,1000} | offensive_tool_keyword | tricky.lnk | VBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and execute | T1027 - T1036 - T1218.010 | TA0002 - TA0003 - TA0008 | N/A | N/A | Phishing | https://github.com/xillwillx/tricky.lnk | 1 | 0 | N/A | N/A | N/A | 2 | 114 | 33 | 2020-12-19T23:42:10Z | 2016-10-26T21:25:06Z | 3556 |
| 43 | * tricky2.ps1* | .{0,1000}\stricky2\.ps1.{0,1000} | offensive_tool_keyword | tricky.lnk | VBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and execute | T1027 - T1036 - T1218.010 | TA0002 - TA0003 - TA0008 | N/A | N/A | Phishing | https://github.com/xillwillx/tricky.lnk | 1 | 0 | N/A | N/A | N/A | 2 | 114 | 33 | 2020-12-19T23:42:10Z | 2016-10-26T21:25:06Z | 3557 |
| 44 | * --vnc localhost:5900 --listen 5980* | .{0,1000}\s\-\-vnc\slocalhost\:5900\s\-\-listen\s5980.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/ms101/EvilKnievelnoVNC | 1 | 0 | #linux | N/A | 9 | 1 | 44 | 8 | 2025-03-08T19:34:41Z | 2024-04-13T22:05:04Z | 3672 |
| 45 | *"Evilginx Mastery Course"* | .{0,1000}\"Evilginx\sMastery\sCourse\".{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #content | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 3837 |
| 46 | *${White}A tool to perform clipboard poisoning attack* | .{0,1000}\$\{White\}A\stool\sto\sperform\sclipboard\spoisoning\sattack.{0,1000} | offensive_tool_keyword | pastehakk | perform clipboard poisoning or paste jacking attack | T1115 | T0001 - T0002 - T0005 | N/A | N/A | Phishing | https://github.com/3xploitGuy/pastehakk | 1 | 0 | #linux #content | N/A | 7 | 1 | 56 | 10 | 2020-06-22T01:17:53Z | 2020-06-17T19:32:24Z | 3937 |
| 47 | *$Green Infecting html file* | .{0,1000}\$Green\sInfecting\shtml\sfile.{0,1000} | offensive_tool_keyword | pastehakk | perform clipboard poisoning or paste jacking attack | T1115 | T0001 - T0002 - T0005 | N/A | N/A | Phishing | https://github.com/3xploitGuy/pastehakk | 1 | 0 | #linux #content | N/A | 7 | 1 | 56 | 10 | 2020-06-22T01:17:53Z | 2020-06-17T19:32:24Z | 3981 |
| 48 | *$Hc2$w$c$rQW$d$s$w$b$Hc2$v$xZp$f$w$V9z$rQW$L$U$xZp* | .{0,1000}\$Hc2\$w\$c\$rQW\$d\$s\$w\$b\$Hc2\$v\$xZp\$f\$w\$V9z\$rQW\$L\$U\$xZp.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 3982 | ||||
| 49 | *$HOME/.tunneler* | .{0,1000}\$HOME\/\.tunneler.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 3984 | ||||
| 50 | *$N0q$x$Hc2$rQW* | .{0,1000}\$N0q\$x\$Hc2\$rQW.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 4002 | ||||
| 51 | *$tunneler_dir/loclx.log* | .{0,1000}\$tunneler_dir\/loclx\.log.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 4024 | ||||
| 52 | *./evil-proxy* | .{0,1000}\.\/evil\-proxy.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | #linux | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 4132 |
| 53 | *.doc.bat* | .{0,1000}\.doc\.bat.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4290 |
| 54 | *.doc.dll* | .{0,1000}\.doc\.dll.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4291 |
| 55 | *.doc.exe* | .{0,1000}\.doc\.exe.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4292 |
| 56 | *.doc.htm* | .{0,1000}\.doc\.htm.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4293 |
| 57 | *.doc.iso* | .{0,1000}\.doc\.iso.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4294 |
| 58 | *.doc.jar* | .{0,1000}\.doc\.jar.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4295 |
| 59 | *.doc.js* | .{0,1000}\.doc\.js.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4296 |
| 60 | *.doc.sfx* | .{0,1000}\.doc\.sfx.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4297 |
| 61 | *.doc.vbs* | .{0,1000}\.doc\.vbs.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4298 |
| 62 | *.docx.bat* | .{0,1000}\.docx\.bat.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4299 |
| 63 | *.docx.exe* | .{0,1000}\.docx\.exe.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4300 |
| 64 | *.docx.htm* | .{0,1000}\.docx\.htm.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4301 |
| 65 | *.docx.iso* | .{0,1000}\.docx\.iso.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4302 |
| 66 | *.docx.jar* | .{0,1000}\.docx\.jar.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4303 |
| 67 | *.docx.js* | .{0,1000}\.docx\.js.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4305 |
| 68 | *.docx.sfx* | .{0,1000}\.docx\.sfx.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4306 |
| 69 | *.docx.vbs* | .{0,1000}\.docx\.vbs.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4307 |
| 70 | *.jpg.exe* | .{0,1000}\.jpg\.exe.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4680 |
| 71 | *.jpg.iso* | .{0,1000}\.jpg\.iso.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4681 |
| 72 | *.lab.evilginx.com* | .{0,1000}\.lab\.evilginx\.com.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 1 | N/A | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 4687 |
| 73 | *.pdf.bat* | .{0,1000}\.pdf\.bat.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4721 |
| 74 | *.pdf.dll* | .{0,1000}\.pdf\.dll.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4722 |
| 75 | *.pdf.exe* | .{0,1000}\.pdf\.exe.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4723 |
| 76 | *.pdf.htm | .{0,1000}\.pdf\.htm.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4724 |
| 77 | *.pdf.iso* | .{0,1000}\.pdf\.iso.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4725 |
| 78 | *.pdf.jar* | .{0,1000}\.pdf\.jar.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4726 |
| 79 | *.pdf.js* | .{0,1000}\.pdf\.js.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4728 |
| 80 | *.pdf.sfx* | .{0,1000}\.pdf\.sfx.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4729 |
| 81 | *.pdf.vbs* | .{0,1000}\.pdf\.vbs.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4730 |
| 82 | *.ppt.bat* | .{0,1000}\.ppt\.bat.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4739 |
| 83 | *.ppt.dll* | .{0,1000}\.ppt\.dll.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4740 |
| 84 | *.ppt.exe* | .{0,1000}\.ppt\.exe.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4741 |
| 85 | *.ppt.htm* | .{0,1000}\.ppt\.htm.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4742 |
| 86 | *.ppt.iso* | .{0,1000}\.ppt\.iso.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4743 |
| 87 | *.ppt.jar* | .{0,1000}\.ppt\.jar.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4744 |
| 88 | *.ppt.js* | .{0,1000}\.ppt\.js.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4745 |
| 89 | *.ppt.sfx* | .{0,1000}\.ppt\.sfx.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4746 |
| 90 | *.ppt.vbs* | .{0,1000}\.ppt\.vbs.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4747 |
| 91 | *.pptx.bat* | .{0,1000}\.pptx\.bat.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4748 |
| 92 | *.pptx.dll* | .{0,1000}\.pptx\.dll.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4749 |
| 93 | *.pptx.exe* | .{0,1000}\.pptx\.exe.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4750 |
| 94 | *.pptx.htm* | .{0,1000}\.pptx\.htm.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4751 |
| 95 | *.pptx.iso* | .{0,1000}\.pptx\.iso.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4752 |
| 96 | *.pptx.jar* | .{0,1000}\.pptx\.jar.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4753 |
| 97 | *.pptx.js* | .{0,1000}\.pptx\.js.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4755 |
| 98 | *.pptx.sfx* | .{0,1000}\.pptx\.sfx.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4756 |
| 99 | *.pptx.vbs* | .{0,1000}\.pptx\.vbs.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4757 |
| 100 | *.py -k * -f *.bat -o *.html* | .{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.bat\s\-o\s.{0,1000}\.html.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 0 | N/A | N/A | 10 | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 4774 |
| 101 | *.py -k * -f *.docm -o *.html* | .{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.docm\s\-o\s.{0,1000}\.html.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 0 | N/A | N/A | 10 | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 4775 |
| 102 | *.py -k * -f *.docx -o *.html* | .{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.docx\s\-o\s.{0,1000}\.html.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 0 | N/A | N/A | 10 | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 4776 |
| 103 | *.py -k * -f *.exe -o *.html* | .{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.exe\s\-o\s.{0,1000}\.html.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 0 | N/A | N/A | 10 | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 4777 |
| 104 | *.py -k * -f *.js -o *.html* | .{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.js\s\-o\s.{0,1000}\.html.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 0 | N/A | N/A | 10 | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 4778 |
| 105 | *.py -k * -f *.pps -o *.html* | .{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.pps\s\-o\s.{0,1000}\.html.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 0 | N/A | N/A | 10 | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 4779 |
| 106 | *.py -k * -f *.ppsx -o *.html* | .{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.ppsx\s\-o\s.{0,1000}\.html.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 0 | N/A | N/A | 10 | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 4780 |
| 107 | *.py -k * -f *.ppt -o *.html* | .{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.ppt\s\-o\s.{0,1000}\.html.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 0 | N/A | N/A | 10 | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 4781 |
| 108 | *.py -k * -f *.ps1 -o *.html* | .{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.ps1\s\-o\s.{0,1000}\.html.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 0 | N/A | N/A | 10 | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 4782 |
| 109 | *.py -k * -f *.xll -o *.html* | .{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.xll\s\-o\s.{0,1000}\.html.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 0 | N/A | N/A | 10 | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 4783 |
| 110 | *.py -k * -f *.xls -o *.html* | .{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.xls\s\-o\s.{0,1000}\.html.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 0 | N/A | N/A | 10 | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 4784 |
| 111 | *.py -k * -f *.xlsb -o *.html* | .{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.xlsb\s\-o\s.{0,1000}\.html.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 0 | N/A | N/A | 10 | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 4785 |
| 112 | *.py -k * -f *.xlsm -o *.html* | .{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.xlsm\s\-o\s.{0,1000}\.html.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 0 | N/A | N/A | 10 | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 4786 |
| 113 | *.py -k * -f *.xlsx -o *.html* | .{0,1000}\.py\s\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.xlsx\s\-o\s.{0,1000}\.html.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 0 | N/A | N/A | 10 | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 4787 |
| 114 | *.py -k * -f *.doc -o *.html* | .{0,1000}\.py\s\-k\s.{0,1000}\s\-f\s.{0,1000}\.doc\s\-o\s.{0,1000}\.html.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 0 | N/A | N/A | 10 | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 4835 |
| 115 | *.rar.exe* | .{0,1000}\.rar\.exe.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4858 |
| 116 | *.rar.iso* | .{0,1000}\.rar\.iso.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4859 |
| 117 | *.rtf.bat* | .{0,1000}\.rtf\.bat.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4873 |
| 118 | *.rtf.dll* | .{0,1000}\.rtf\.dll.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4874 |
| 119 | *.rtf.exe* | .{0,1000}\.rtf\.exe.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4875 |
| 120 | *.rtf.htm* | .{0,1000}\.rtf\.htm.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4876 |
| 121 | *.rtf.jar* | .{0,1000}\.rtf\.jar.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4877 |
| 122 | *.rtf.js* | .{0,1000}\.rtf\.js.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4878 |
| 123 | *.rtf.sfx* | .{0,1000}\.rtf\.sfx.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4879 |
| 124 | *.rtf.vbs* | .{0,1000}\.rtf\.vbs.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4880 |
| 125 | *.trycloudfare.com*DavWWWRoot* | .{0,1000}\.trycloudfare\.com.{0,1000}DavWWWRoot.{0,1000} | greyware_tool_keyword | trycloudflare.com | The subdomain .trycloudflare.com is a temporary hostname provided by Cloudflare Tunnel - It allows users to expose local services to the internet without needing to configure port forwarding or a public IP - attackers frequently abuse it for malicious activities | T1071.001 - T1090 - T1583.003 - T1102 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | Phishing | https://www.forcepoint.com/blog/x-labs/asyncrat-python-trycloudflare-malware | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4923 |
| 126 | *.tunneler/cf.log* | .{0,1000}\.tunneler\/cf\.log.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 4925 | ||||
| 127 | *.tunneler/cloudflared* | .{0,1000}\.tunneler\/cloudflared.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 4926 | ||||
| 128 | *.tunneler/loclx* | .{0,1000}\.tunneler\/loclx.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 4927 | ||||
| 129 | *.tunneler/loclx.log* | .{0,1000}\.tunneler\/loclx\.log.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 4928 | ||||
| 130 | *.txt.bat* | .{0,1000}\.txt\.bat.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4933 |
| 131 | *.txt.dll* | .{0,1000}\.txt\.dll.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4934 |
| 132 | *.txt.exe* | .{0,1000}\.txt\.exe.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4935 |
| 133 | *.txt.htm* | .{0,1000}\.txt\.htm.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4936 |
| 134 | *.txt.iso* | .{0,1000}\.txt\.iso.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4937 |
| 135 | *.txt.jar* | .{0,1000}\.txt\.jar.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4938 |
| 136 | *.txt.js | .{0,1000}\.txt\.js | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4940 |
| 137 | *.txt.sfx* | .{0,1000}\.txt\.sfx.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4941 |
| 138 | *.txt.vbs* | .{0,1000}\.txt\.vbs.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4942 |
| 139 | *.xls.bat* | .{0,1000}\.xls\.bat.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4957 |
| 140 | *.xls.dll* | .{0,1000}\.xls\.dll.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4958 |
| 141 | *.xls.exe* | .{0,1000}\.xls\.exe.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4959 |
| 142 | *.xls.htm* | .{0,1000}\.xls\.htm.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4960 |
| 143 | *.xls.iso* | .{0,1000}\.xls\.iso.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4961 |
| 144 | *.xls.jar* | .{0,1000}\.xls\.jar.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4962 |
| 145 | *.xls.js* | .{0,1000}\.xls\.js.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4963 |
| 146 | *.xls.sfx* | .{0,1000}\.xls\.sfx.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4964 |
| 147 | *.xls.vbs* | .{0,1000}\.xls\.vbs.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4965 |
| 148 | *.xlsx.bat* | .{0,1000}\.xlsx\.bat.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4966 |
| 149 | *.xlsx.dll* | .{0,1000}\.xlsx\.dll.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4967 |
| 150 | *.xlsx.exe* | .{0,1000}\.xlsx\.exe.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4968 |
| 151 | *.xlsx.htm* | .{0,1000}\.xlsx\.htm.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4969 |
| 152 | *.xlsx.iso* | .{0,1000}\.xlsx\.iso.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4970 |
| 153 | *.xlsx.jar* | .{0,1000}\.xlsx\.jar.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4971 |
| 154 | *.xlsx.js* | .{0,1000}\.xlsx\.js.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4973 |
| 155 | *.xlsx.sfx* | .{0,1000}\.xlsx\.sfx.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4974 |
| 156 | *.xlsx.vbs* | .{0,1000}\.xlsx\.vbs.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4975 |
| 157 | *.zip.exe* | .{0,1000}\.zip\.exe.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4977 |
| 158 | *.zip.iso* | .{0,1000}\.zip\.iso.{0,1000} | offensive_tool_keyword | _ | Suspicious extensions files | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 - TA0007 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4978 |
| 159 | */.evilginx/* | .{0,1000}\/\.evilginx\/.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #linux | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 5013 |
| 160 | */.localxpose/.access* | .{0,1000}\/\.localxpose\/\.access.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | #linux | N/A | 10 | N/A | 5021 | ||||
| 161 | */365-Stealer.git* | .{0,1000}\/365\-Stealer\.git.{0,1000} | offensive_tool_keyword | 365-Stealer | 365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack | T1111 - T1566.001 - T1078.004 | TA0004 - TA0001 - TA0040 | N/A | N/A | Phishing | https://github.com/AlteredSecurity/365-Stealer | 1 | 1 | N/A | N/A | 10 | 5 | 488 | 89 | 2024-06-08T21:03:50Z | 2020-09-20T18:22:36Z | 5086 |
| 162 | */agent/stagers/dropbox.py* | .{0,1000}\/agent\/stagers\/dropbox\.py.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 1 | N/A | N/A | 10 | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 5234 |
| 163 | */bin/bash -c "php -q -S 0.0.0.0:80 &" > /dev/null 2>&1* | .{0,1000}\/bin\/bash\s\-c\s\"php\s\-q\s\-S\s0\.0\.0\.0\:80\s\&\"\s\>\s\/dev\/null\s2\>\&1.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 0 | #linux | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 5621 |
| 164 | */CamHacker-*.png* | .{0,1000}\/CamHacker\-.{0,1000}\.png.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 1 | N/A | N/A | 10 | N/A | 5941 | ||||
| 165 | */CamHacker.git* | .{0,1000}\/CamHacker\.git.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 1 | N/A | N/A | 10 | N/A | 5942 | ||||
| 166 | */ClickJack.exe | .{0,1000}\/ClickJack\.exe | offensive_tool_keyword | clickjack | automate abuse of clickonce applications | T1210 - T1204 - T1071.001 | TA0001 - TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/trustedsec/The_Shelf | 1 | 1 | N/A | N/A | 10 | 3 | 247 | 14 | 2024-11-25T19:33:34Z | 2024-05-22T14:31:52Z | 6061 |
| 167 | */CredPhisher/* | .{0,1000}\/CredPhisher\/.{0,1000} | offensive_tool_keyword | CredPhisher | Prompts the current user for their credentials using the CredUIPromptForWindowsCredentials WinAPI function | T1056.002 - T1111 | TA0004 | N/A | N/A | Phishing | https://github.com/matterpreter/OffensiveCSharp/tree/master/CredPhisher | 1 | 1 | N/A | N/A | 10 | 10 | 1416 | 250 | 2023-02-06T14:56:26Z | 2019-02-06T00:32:29Z | 6265 |
| 168 | */domainhunter* | .{0,1000}\/domainhunter.{0,1000} | offensive_tool_keyword | domainhunter | Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names | T1583.002 - T1568.002 | TA0011 - TA0009 | N/A | N/A | Phishing | https://github.com/threatexpress/domainhunter | 1 | 1 | N/A | N/A | N/A | 10 | 1587 | 292 | 2024-06-06T21:01:21Z | 2017-03-01T11:16:26Z | 6723 |
| 169 | */Downloads/Keylogger.txt* | .{0,1000}\/Downloads\/Keylogger\.txt.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 0 | #linux | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 6769 |
| 170 | */Downloads/keypress.log* | .{0,1000}\/Downloads\/keypress\.log.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 0 | #linux | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 6770 |
| 171 | */EmbedInHTML.git* | .{0,1000}\/EmbedInHTML\.git.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 1 | N/A | N/A | 10 | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 6925 |
| 172 | */EmbedInHTML/* | .{0,1000}\/EmbedInHTML\/.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 1 | N/A | N/A | N/A | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 6926 |
| 173 | */EvilClippy-*.zip* | .{0,1000}\/EvilClippy\-.{0,1000}\.zip.{0,1000} | offensive_tool_keyword | EvilClippy | A cross-platform assistant for creating malicious MS Office documents | T1566.001 - T1059.001 - T1204.002 | TA0004 - TA0002 | N/A | N/A | Phishing | https://github.com/outflanknl/EvilClippy | 1 | 1 | N/A | N/A | 10 | 10 | 2165 | 402 | 2023-12-27T12:37:47Z | 2019-03-26T12:14:03Z | 7073 |
| 174 | */evilclippy.cs* | .{0,1000}\/evilclippy\.cs.{0,1000} | offensive_tool_keyword | EvilClippy | A cross-platform assistant for creating malicious MS Office documents | T1566.001 - T1059.001 - T1204.002 | TA0004 - TA0002 | N/A | N/A | Phishing | https://github.com/outflanknl/EvilClippy | 1 | 1 | N/A | N/A | 10 | 10 | 2165 | 402 | 2023-12-27T12:37:47Z | 2019-03-26T12:14:03Z | 7074 |
| 175 | */EvilClippy.git* | .{0,1000}\/EvilClippy\.git.{0,1000} | offensive_tool_keyword | EvilClippy | A cross-platform assistant for creating malicious MS Office documents | T1566.001 - T1059.001 - T1204.002 | TA0004 - TA0002 | N/A | N/A | Phishing | https://github.com/outflanknl/EvilClippy | 1 | 1 | N/A | N/A | 10 | 10 | 2165 | 402 | 2023-12-27T12:37:47Z | 2019-03-26T12:14:03Z | 7075 |
| 176 | */evilginx* | .{0,1000}\/evilginx.{0,1000} | offensive_tool_keyword | gophish | Combination of evilginx2 and GoPhish | T1565-002 - T1565-003 - T1565-012 - T1110 - T1056-001 - T1113 | TA0002 - TA0003 | N/A | Black Basta | Phishing | https://github.com/fin3ss3g0d/evilgophish | 1 | 1 | N/A | N/A | 10 | 10 | 1762 | 340 | 2024-06-15T17:48:11Z | 2022-09-07T02:47:43Z | 7076 |
| 177 | */evilginx2.git* | .{0,1000}\/evilginx2\.git.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 1 | N/A | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 7077 |
| 178 | */evilginx2/* | .{0,1000}\/evilginx2\/.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 1 | #linux | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 7078 |
| 179 | */EvilnoVNC.git* | .{0,1000}\/EvilnoVNC\.git.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 1 | N/A | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 7082 |
| 180 | */evil-proxy.git* | .{0,1000}\/evil\-proxy\.git.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 1 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 7083 |
| 181 | */evil-proxy.rb* | .{0,1000}\/evil\-proxy\.rb.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 1 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 7084 |
| 182 | */evil-proxy/* | .{0,1000}\/evil\-proxy\/.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | #linux | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 7085 |
| 183 | */evilqr.git* | .{0,1000}\/evilqr\.git.{0,1000} | offensive_tool_keyword | evilqr | Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice | T1566.002 - T1204.001 - T1192 | TA0001 - TA0005 | N/A | N/A | Phishing | https://github.com/kgretzky/evilqr | 1 | 1 | N/A | N/A | N/A | 3 | 292 | 45 | 2024-06-18T11:27:23Z | 2023-06-20T12:58:09Z | 7086 |
| 184 | */ExtensionSpoof.exe* | .{0,1000}\/ExtensionSpoof\.exe.{0,1000} | offensive_tool_keyword | ExtensionSpoofer | Spoof file icons and extensions in Windows | T1036 - T1027.005 - T1218 | TA0005 - TA0040 | N/A | N/A | Phishing | https://github.com/henriksb/ExtensionSpoofer | 1 | 1 | N/A | N/A | 9 | 2 | 179 | 65 | 2024-12-12T18:05:28Z | 2017-11-11T16:02:17Z | 7155 |
| 185 | */ExtensionSpoofer.git* | .{0,1000}\/ExtensionSpoofer\.git.{0,1000} | offensive_tool_keyword | ExtensionSpoofer | Spoof file icons and extensions in Windows | T1036 - T1027.005 - T1218 | TA0005 - TA0040 | N/A | N/A | Phishing | https://github.com/henriksb/ExtensionSpoofer | 1 | 1 | N/A | N/A | 9 | 2 | 179 | 65 | 2024-12-12T18:05:28Z | 2017-11-11T16:02:17Z | 7156 |
| 186 | */gophish.db* | .{0,1000}\/gophish\.db.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/Evilginx-Phishing-Infra-Setup | 1 | 0 | #linux | N/A | 10 | 4 | 391 | 67 | 2024-12-12T04:13:02Z | 2024-06-08T10:19:45Z | 7584 |
| 187 | */gophish.db* | .{0,1000}\/gophish\.db.{0,1000} | offensive_tool_keyword | gophish | Open-Source Phishing Toolkit | T1566-001 - T1566-002 - T1566-003 - T1056-001 - T1113 - T1567-001 | TA0002 - TA0003 | N/A | Black Basta | Phishing | https://github.com/gophish/gophish | 1 | 1 | N/A | N/A | 10 | 10 | 12483 | 2528 | 2024-09-23T04:24:43Z | 2013-11-18T23:26:43Z | 7585 |
| 188 | */gophish/* | .{0,1000}\/gophish\/.{0,1000} | offensive_tool_keyword | gophish | Open-Source Phishing Toolkit | T1566-001 - T1566-002 - T1566-003 - T1056-001 - T1113 - T1567-001 | TA0002 - TA0003 | N/A | Black Basta | Phishing | https://github.com/gophish/gophish | 1 | 1 | N/A | N/A | 10 | 10 | 12483 | 2528 | 2024-09-23T04:24:43Z | 2013-11-18T23:26:43Z | 7586 |
| 189 | */gophish_admin.crt* | .{0,1000}\/gophish_admin\.crt.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/Evilginx-Phishing-Infra-Setup | 1 | 0 | #linux | N/A | 10 | 4 | 391 | 67 | 2024-12-12T04:13:02Z | 2024-06-08T10:19:45Z | 7587 |
| 190 | */gophish_admin.key* | .{0,1000}\/gophish_admin\.key.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/Evilginx-Phishing-Infra-Setup | 1 | 0 | #linux | N/A | 10 | 4 | 391 | 67 | 2024-12-12T04:13:02Z | 2024-06-08T10:19:45Z | 7588 |
| 191 | */HTMLSmuggler.git* | .{0,1000}\/HTMLSmuggler\.git.{0,1000} | offensive_tool_keyword | HTMLSmuggler | HTML Smuggling generator&obfuscator for your Red Team operations | T1564.001 - T1027 - T1566 | TA0005 | N/A | N/A | Phishing | https://github.com/D00Movenok/HTMLSmuggler | 1 | 1 | N/A | N/A | 10 | 2 | 162 | 19 | 2024-02-27T23:03:55Z | 2023-07-02T08:10:59Z | 7824 |
| 192 | */HTMLSmuggler/* | .{0,1000}\/HTMLSmuggler\/.{0,1000} | offensive_tool_keyword | HTMLSmuggler | HTML Smuggling generator&obfuscator for your Red Team operations | T1564.001 - T1027 - T1566 | TA0005 | N/A | N/A | Phishing | https://github.com/D00Movenok/HTMLSmuggler | 1 | 1 | N/A | N/A | 10 | 2 | 162 | 19 | 2024-02-27T23:03:55Z | 2023-07-02T08:10:59Z | 7825 |
| 193 | */keygen.exe* | .{0,1000}\/keygen\.exe.{0,1000} | greyware_tool_keyword | _ | generic suspicious keyword keygen.exe observed in multiple cracked software often packed with malwares | T1204 - T1027 - T1059 - T1055 - T1060 - T1195 | TA0005 - TA0002 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 8341 |
| 194 | */lnk2pwn.git* | .{0,1000}\/lnk2pwn\.git.{0,1000} | offensive_tool_keyword | lnk2pwn | Malicious Shortcut(.lnk) Generator | T1204 - T1059.007 | TA0001 - TA0002 | N/A | N/A | Phishing | https://github.com/it-gorillaz/lnk2pwn | 1 | 1 | N/A | N/A | 8 | 2 | 193 | 34 | 2018-11-23T17:18:49Z | 2018-11-23T00:12:48Z | 8560 |
| 195 | */lnk2pwn-1.0.0.zip* | .{0,1000}\/lnk2pwn\-1\.0\.0\.zip.{0,1000} | offensive_tool_keyword | lnk2pwn | Malicious Shortcut(.lnk) Generator | T1204 - T1059.007 | TA0001 - TA0002 | N/A | N/A | Phishing | https://github.com/it-gorillaz/lnk2pwn | 1 | 1 | N/A | N/A | 8 | 2 | 193 | 34 | 2018-11-23T17:18:49Z | 2018-11-23T00:12:48Z | 8561 |
| 196 | */login/e1837f4d-1d0c-49b8-a242-8f653226c137* | .{0,1000}\/login\/e1837f4d\-1d0c\-49b8\-a242\-8f653226c137.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 1 | N/A | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 8611 |
| 197 | */mrd0x.html* | .{0,1000}\/mrd0x\.html.{0,1000} | offensive_tool_keyword | PWA-Phishing | Phishing with Progressive Web Apps and UI manipulation | T1071.003 - T1204.002 - T1608.003 - T1071.004 | TA0006 | N/A | N/A | Phishing | https://github.com/mrd0x/PWA-Phishing | 1 | 1 | N/A | N/A | 10 | 3 | 288 | 52 | 2024-06-16T17:47:15Z | 2024-06-09T19:47:52Z | 8907 |
| 198 | */ngrok http 3333 > /dev/null 2>&1* | .{0,1000}\/ngrok\shttp\s3333\s\>\s\/dev\/null\s2\>\&1.{0,1000} | offensive_tool_keyword | saycheese | Grab target's webcam shots by link | T1213 - T1071 - T1102 - T1123 - T1185 - T1200 | TA0001 - TA0005 - TA0009 - TA0011 | N/A | N/A | Phishing | https://github.com/hangetzzu/saycheese | 1 | 0 | #linux | N/A | 9 | 10 | 1175 | 962 | 2024-06-18T23:39:41Z | 2019-04-29T04:07:00Z | 9135 |
| 199 | */noVNC/index.html* | .{0,1000}\/noVNC\/index\.html.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/ms101/EvilKnievelnoVNC | 1 | 0 | #linux | N/A | 9 | 1 | 44 | 8 | 2025-03-08T19:34:41Z | 2024-04-13T22:05:04Z | 9247 |
| 200 | */noVNC/utils/novnc_proxy* | .{0,1000}\/noVNC\/utils\/novnc_proxy.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 0 | #linux | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 9248 |
| 201 | */noVNC/vnc_lite.html* | .{0,1000}\/noVNC\/vnc_lite\.html.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/ms101/EvilKnievelnoVNC | 1 | 0 | #linux | N/A | 9 | 1 | 44 | 8 | 2025-03-08T19:34:41Z | 2024-04-13T22:05:04Z | 9249 |
| 202 | */pastehakk.git* | .{0,1000}\/pastehakk\.git.{0,1000} | offensive_tool_keyword | pastehakk | perform clipboard poisoning or paste jacking attack | T1115 | T0001 - T0002 - T0005 | N/A | N/A | Phishing | https://github.com/3xploitGuy/pastehakk | 1 | 1 | N/A | N/A | 7 | 1 | 56 | 10 | 2020-06-22T01:17:53Z | 2020-06-17T19:32:24Z | 9541 |
| 203 | */pastehakk.sh* | .{0,1000}\/pastehakk\.sh.{0,1000} | offensive_tool_keyword | pastehakk | perform clipboard poisoning or paste jacking attack | T1115 | T0001 - T0002 - T0005 | N/A | N/A | Phishing | https://github.com/3xploitGuy/pastehakk | 1 | 1 | #linux | N/A | 7 | 1 | 56 | 10 | 2020-06-22T01:17:53Z | 2020-06-17T19:32:24Z | 9542 |
| 204 | */PAYMENTS.exe* | .{0,1000}\/PAYMENTS\.exe.{0,1000} | greyware_tool_keyword | _ | suspicious file name - has been used by threat actors | T1566 | TA0001 | N/A | N/A | Phishing | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 9567 |
| 205 | */phishery.exe* | .{0,1000}\/phishery\.exe.{0,1000} | offensive_tool_keyword | phishery | Phishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document. | T1566.001 - T1071 - T1204.002 | TA0001 | N/A | BERSERK BEAR | Phishing | https://github.com/ryhanson/phishery | 1 | 1 | N/A | N/A | 9 | 10 | 993 | 209 | 2017-09-11T15:42:10Z | 2016-09-25T02:19:24Z | 9661 |
| 206 | */phishery.git* | .{0,1000}\/phishery\.git.{0,1000} | offensive_tool_keyword | phishery | Phishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document. | T1566.001 - T1071 - T1204.002 | TA0001 | N/A | BERSERK BEAR | Phishing | https://github.com/ryhanson/phishery | 1 | 1 | N/A | N/A | 9 | 10 | 993 | 209 | 2017-09-11T15:42:10Z | 2016-09-25T02:19:24Z | 9662 |
| 207 | */phishery/releases/download/* | .{0,1000}\/phishery\/releases\/download\/.{0,1000} | offensive_tool_keyword | phishery | Phishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document. | T1566.001 - T1071 - T1204.002 | TA0001 | N/A | BERSERK BEAR | Phishing | https://github.com/ryhanson/phishery | 1 | 1 | N/A | N/A | 9 | 10 | 993 | 209 | 2017-09-11T15:42:10Z | 2016-09-25T02:19:24Z | 9663 |
| 208 | */phishing-HTML-linter.py* | .{0,1000}\/phishing\-HTML\-linter\.py.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/Evilginx-Phishing-Infra-Setup | 1 | 0 | #linux | N/A | 10 | 4 | 391 | 67 | 2024-12-12T04:13:02Z | 2024-06-08T10:19:45Z | 9668 |
| 209 | */phishlets/example.yaml* | .{0,1000}\/phishlets\/example\.yaml.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 1 | #linux | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 9670 |
| 210 | */PWA-Phishing.git* | .{0,1000}\/PWA\-Phishing\.git.{0,1000} | offensive_tool_keyword | PWA-Phishing | Phishing with Progressive Web Apps and UI manipulation | T1071.003 - T1204.002 - T1608.003 - T1071.004 | TA0006 | N/A | N/A | Phishing | https://github.com/mrd0x/PWA-Phishing | 1 | 1 | N/A | N/A | 10 | 3 | 288 | 52 | 2024-06-16T17:47:15Z | 2024-06-09T19:47:52Z | 10035 |
| 211 | */recaptcha-phish.git* | .{0,1000}\/recaptcha\-phish\.git.{0,1000} | offensive_tool_keyword | recaptcha-phish | Phishing with a fake reCAPTCHA | T1566.001 - T1204.002 - T1071.003 | TA0001 - TA0002 | Lumma Stealer | N/A | Phishing | https://github.com/JohnHammond/recaptcha-phish | 1 | 1 | N/A | N/A | 10 | 6 | 534 | 104 | 2024-09-13T11:18:29Z | 2024-09-13T07:00:40Z | 10252 |
| 212 | */recaptcha-phish-main* | .{0,1000}\/recaptcha\-phish\-main.{0,1000} | offensive_tool_keyword | recaptcha-phish | Phishing with a fake reCAPTCHA | T1566.001 - T1204.002 - T1071.003 | TA0001 - TA0002 | Lumma Stealer | N/A | Phishing | https://github.com/JohnHammond/recaptcha-phish | 1 | 1 | N/A | N/A | 10 | 6 | 534 | 104 | 2024-09-13T11:18:29Z | 2024-09-13T07:00:40Z | 10253 |
| 213 | */releases/latest/download/cloudflared-darwin-amd64.tgz* | .{0,1000}\/releases\/latest\/download\/cloudflared\-darwin\-amd64\.tgz.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 1 | #linux | N/A | 10 | N/A | 10350 | ||||
| 214 | */saycheese.html* | .{0,1000}\/saycheese\.html.{0,1000} | offensive_tool_keyword | saycheese | Grab target's webcam shots by link | T1213 - T1071 - T1102 - T1123 - T1185 - T1200 | TA0001 - TA0005 - TA0009 - TA0011 | N/A | N/A | Phishing | https://github.com/hangetzzu/saycheese | 1 | 1 | N/A | N/A | 9 | 10 | 1175 | 962 | 2024-06-18T23:39:41Z | 2019-04-29T04:07:00Z | 10693 |
| 215 | */saycheese.sh* | .{0,1000}\/saycheese\.sh.{0,1000} | offensive_tool_keyword | saycheese | Grab target's webcam shots by link | T1213 - T1071 - T1102 - T1123 - T1185 - T1200 | TA0001 - TA0005 - TA0009 - TA0011 | N/A | N/A | Phishing | https://github.com/hangetzzu/saycheese | 1 | 1 | N/A | N/A | 9 | 10 | 1175 | 962 | 2024-06-18T23:39:41Z | 2019-04-29T04:07:00Z | 10694 |
| 216 | */smuggler.py* | .{0,1000}\/smuggler\.py.{0,1000} | offensive_tool_keyword | smuggler.py | HTML Smuggling Generator | T1564.001 - T1027 - T1566 | TA0005 | N/A | N/A | Phishing | https://github.com/infosecn1nja/red-team-scripts/blob/main/smuggler.py | 1 | 1 | N/A | N/A | 9 | 3 | 299 | 55 | 2024-08-08T06:11:06Z | 2023-01-15T22:37:34Z | 11448 |
| 217 | */start.sh dynamic * | .{0,1000}\/start\.sh\sdynamic\s.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 0 | #linux | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 11657 |
| 218 | */startVNC.sh* | .{0,1000}\/startVNC\.sh.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 0 | #linux | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 11661 |
| 219 | */Teamphisher.txt* | .{0,1000}\/Teamphisher\.txt.{0,1000} | offensive_tool_keyword | teamsphisher | Send phishing messages and attachments to Microsoft Teams users | T1566.001 - T1566.002 - T1204.001 | TA0001 - TA0005 | N/A | Black Basta | Phishing | https://github.com/Octoberfest7/TeamsPhisher | 1 | 1 | N/A | N/A | N/A | 10 | 1073 | 138 | 2024-06-19T21:41:55Z | 2023-07-03T02:19:47Z | 11833 |
| 220 | */Teamphisher/targets.txt* | .{0,1000}\/Teamphisher\/targets\.txt.{0,1000} | offensive_tool_keyword | teamsphisher | Send phishing messages and attachments to Microsoft Teams users | T1566.001 - T1566.002 - T1204.001 | TA0001 - TA0005 | N/A | Black Basta | Phishing | https://github.com/Octoberfest7/TeamsPhisher | 1 | 1 | N/A | N/A | N/A | 10 | 1073 | 138 | 2024-06-19T21:41:55Z | 2023-07-03T02:19:47Z | 11834 |
| 221 | */tmp/resolution.txt*server.sh* | .{0,1000}\/tmp\/resolution\.txt.{0,1000}server\.sh.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 0 | #linux | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 11990 |
| 222 | */tricky.lnk.git* | .{0,1000}\/tricky\.lnk\.git.{0,1000} | offensive_tool_keyword | tricky.lnk | VBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and execute | T1027 - T1036 - T1218.010 | TA0002 - TA0003 - TA0008 | N/A | N/A | Phishing | https://github.com/xillwillx/tricky.lnk | 1 | 1 | N/A | N/A | N/A | 2 | 114 | 33 | 2020-12-19T23:42:10Z | 2016-10-26T21:25:06Z | 12087 |
| 223 | */tricky.ps1* | .{0,1000}\/tricky\.ps1.{0,1000} | offensive_tool_keyword | tricky.lnk | VBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and execute | T1027 - T1036 - T1218.010 | TA0002 - TA0003 - TA0008 | N/A | N/A | Phishing | https://github.com/xillwillx/tricky.lnk | 1 | 1 | N/A | N/A | N/A | 2 | 114 | 33 | 2020-12-19T23:42:10Z | 2016-10-26T21:25:06Z | 12088 |
| 224 | */tricky.vbs* | .{0,1000}\/tricky\.vbs.{0,1000} | offensive_tool_keyword | tricky.lnk | VBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and execute | T1027 - T1036 - T1218.010 | TA0002 - TA0003 - TA0008 | N/A | N/A | Phishing | https://github.com/xillwillx/tricky.lnk | 1 | 1 | N/A | N/A | N/A | 2 | 114 | 33 | 2020-12-19T23:42:10Z | 2016-10-26T21:25:06Z | 12089 |
| 225 | */tricky2.ps1* | .{0,1000}\/tricky2\.ps1.{0,1000} | offensive_tool_keyword | tricky.lnk | VBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and execute | T1027 - T1036 - T1218.010 | TA0002 - TA0003 - TA0008 | N/A | N/A | Phishing | https://github.com/xillwillx/tricky.lnk | 1 | 1 | N/A | N/A | N/A | 2 | 114 | 33 | 2020-12-19T23:42:10Z | 2016-10-26T21:25:06Z | 12090 |
| 226 | */usr/share/evilginx* | .{0,1000}\/usr\/share\/evilginx.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #linux | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 12374 |
| 227 | */utils/novnc_proxy* | .{0,1000}\/utils\/novnc_proxy.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/ms101/EvilKnievelnoVNC | 1 | 0 | #linux | N/A | 9 | 1 | 44 | 8 | 2025-03-08T19:34:41Z | 2024-04-13T22:05:04Z | 12384 |
| 228 | */var/log/evilginx* | .{0,1000}\/var\/log\/evilginx.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #linux | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 12404 |
| 229 | */VisualBasicObfuscator* | .{0,1000}\/VisualBasicObfuscator.{0,1000} | offensive_tool_keyword | phishing-HTML-linter | Phishing and Social-Engineering related scripts | T1566.001 - T1056.001 | TA0040 - TA0001 | N/A | N/A | Phishing | https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing | 1 | 1 | N/A | N/A | 10 | 10 | 2689 | 527 | 2023-06-27T19:16:49Z | 2018-02-02T21:24:03Z | 12458 |
| 230 | */windows-login-phish* | .{0,1000}\/windows\-login\-phish.{0,1000} | offensive_tool_keyword | windows-login-phish | Windows Login Phishing page This is a windows maching login page designed using HTML CSS and JS. This can be used for red teaming or cybersecurity awareness related purposes | T1566 | N/A | N/A | N/A | Phishing | https://github.com/CipherKill/windows-login-phish | 1 | 1 | N/A | N/A | N/A | 1 | 17 | 6 | 2022-03-25T05:49:01Z | 2022-03-13T20:02:15Z | 12608 |
| 231 | *@mitm_pattern = * | .{0,1000}\@mitm_pattern\s\=\s.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 12880 |
| 232 | *@mitm_port = * | .{0,1000}\@mitm_port\s\=\s.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 12881 |
| 233 | *@mitm_servers =* | .{0,1000}\@mitm_servers\s\=.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 12882 |
| 234 | *[!] Looks like Victim * doesn't have office365 Licence!* | .{0,1000}\[!\]\sLooks\slike\sVictim\s.{0,1000}\sdoesn\'t\shave\soffice365\sLicence!.{0,1000} | offensive_tool_keyword | 365-Stealer | 365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack | T1111 - T1566.001 - T1078.004 | TA0004 - TA0001 - TA0040 | N/A | N/A | Phishing | https://github.com/AlteredSecurity/365-Stealer | 1 | 0 | #content | N/A | 10 | 5 | 488 | 89 | 2024-06-08T21:03:50Z | 2020-09-20T18:22:36Z | 12944 |
| 235 | *[!] Stealing processes delayed with * | .{0,1000}\[!\]\sStealing\sprocesses\sdelayed\swith\s.{0,1000} | offensive_tool_keyword | 365-Stealer | 365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack | T1111 - T1566.001 - T1078.004 | TA0004 - TA0001 - TA0040 | N/A | N/A | Phishing | https://github.com/AlteredSecurity/365-Stealer | 1 | 0 | #content | N/A | 10 | 5 | 488 | 89 | 2024-06-08T21:03:50Z | 2020-09-20T18:22:36Z | 12961 |
| 236 | *[!] Swithed to custom stealing. * | .{0,1000}\[!\]\sSwithed\sto\scustom\sstealing\.\s.{0,1000} | offensive_tool_keyword | 365-Stealer | 365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack | T1111 - T1566.001 - T1078.004 | TA0004 - TA0001 - TA0040 | N/A | N/A | Phishing | https://github.com/AlteredSecurity/365-Stealer | 1 | 0 | #content | N/A | 10 | 5 | 488 | 89 | 2024-06-08T21:03:50Z | 2020-09-20T18:22:36Z | 12963 |
| 237 | *[!] This application can not be injected* | .{0,1000}\[!\]\sThis\sapplication\scan\snot\sbe\sinjected.{0,1000} | offensive_tool_keyword | clickjack | automate abuse of clickonce applications | T1210 - T1204 - T1071.001 | TA0001 - TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/trustedsec/The_Shelf | 1 | 0 | #content | N/A | 10 | 3 | 247 | 14 | 2024-11-25T19:33:34Z | 2024-05-22T14:31:52Z | 12968 |
| 238 | *[+] This application is injectable!* | .{0,1000}\[\+\]\sThis\sapplication\sis\sinjectable!.{0,1000} | offensive_tool_keyword | clickjack | automate abuse of clickonce applications | T1210 - T1204 - T1071.001 | TA0001 - TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/trustedsec/The_Shelf | 1 | 0 | #content | N/A | 10 | 3 | 247 | 14 | 2024-11-25T19:33:34Z | 2024-05-22T14:31:52Z | 13370 |
| 239 | *[+] Victim * have office365 Licence!* | .{0,1000}\[\+\]\sVictim\s.{0,1000}\shave\soffice365\sLicence!.{0,1000} | offensive_tool_keyword | 365-Stealer | 365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack | T1111 - T1566.001 - T1078.004 | TA0004 - TA0001 - TA0040 | N/A | N/A | Phishing | https://github.com/AlteredSecurity/365-Stealer | 1 | 0 | #content | N/A | 10 | 5 | 488 | 89 | 2024-06-08T21:03:50Z | 2020-09-20T18:22:36Z | 13417 |
| 240 | *[CamHacker]* | .{0,1000}\[CamHacker\].{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 13448 | ||||
| 241 | *\CamHacker\* | .{0,1000}\\CamHacker\\.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 14464 | ||||
| 242 | *\ClickJack.csproj* | .{0,1000}\\ClickJack\.csproj.{0,1000} | offensive_tool_keyword | clickjack | automate abuse of clickonce applications | T1210 - T1204 - T1071.001 | TA0001 - TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/trustedsec/The_Shelf | 1 | 0 | N/A | N/A | 10 | 3 | 247 | 14 | 2024-11-25T19:33:34Z | 2024-05-22T14:31:52Z | 14542 |
| 243 | *\ClickJack.exe | .{0,1000}\\ClickJack\.exe | offensive_tool_keyword | clickjack | automate abuse of clickonce applications | T1210 - T1204 - T1071.001 | TA0001 - TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/trustedsec/The_Shelf | 1 | 0 | N/A | N/A | 10 | 3 | 247 | 14 | 2024-11-25T19:33:34Z | 2024-05-22T14:31:52Z | 14543 |
| 244 | *\Content\.Outlook\*\*.rdp* | .{0,100}\\Content\.Outlook\\[A-Z0-9]{8}\\[^\\]{1,255}\.rdp.{0,100} | greyware_tool_keyword | rdp | rdp file received in emails - abused by attackers | T1204 - T1566 - T1078 - T1105 | TA0001 - TA0002 - TA0010 - TA0011 | N/A | Midnight Blizzard - APT29 - UNC2452 - Cozy Bear | Phishing | https://www.microsoft.com/en-us/security/blog/2024/10/29/midnight-blizzard-conducts-large-scale-spear-phishing-campaign-using-rdp-files | 1 | 0 | N/A | https://x.com/cyb3rops/status/1851880158640099675 | 9 | 8 | N/A | N/A | N/A | N/A | 14616 |
| 245 | *\Desktop\FakeText.lnk* | .{0,1000}\\Desktop\\FakeText\.lnk.{0,1000} | offensive_tool_keyword | tricky.lnk | VBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and execute | T1027 - T1036 - T1218.010 | TA0002 - TA0003 - TA0008 | N/A | N/A | Phishing | https://github.com/xillwillx/tricky.lnk | 1 | 0 | N/A | N/A | N/A | 2 | 114 | 33 | 2020-12-19T23:42:10Z | 2016-10-26T21:25:06Z | 14911 |
| 246 | *\EvilClippy-*.zip* | .{0,1000}\\EvilClippy\-.{0,1000}\.zip.{0,1000} | offensive_tool_keyword | EvilClippy | A cross-platform assistant for creating malicious MS Office documents | T1566.001 - T1059.001 - T1204.002 | TA0004 - TA0002 | N/A | N/A | Phishing | https://github.com/outflanknl/EvilClippy | 1 | 0 | N/A | N/A | 10 | 10 | 2165 | 402 | 2023-12-27T12:37:47Z | 2019-03-26T12:14:03Z | 15344 |
| 247 | *\evilclippy.cs* | .{0,1000}\\evilclippy\.cs.{0,1000} | offensive_tool_keyword | EvilClippy | A cross-platform assistant for creating malicious MS Office documents | T1566.001 - T1059.001 - T1204.002 | TA0004 - TA0002 | N/A | N/A | Phishing | https://github.com/outflanknl/EvilClippy | 1 | 0 | N/A | N/A | 10 | 10 | 2165 | 402 | 2023-12-27T12:37:47Z | 2019-03-26T12:14:03Z | 15345 |
| 248 | *\evilginx2\* | .{0,1000}\\evilginx2\\.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | N/A | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 15346 |
| 249 | *\EvilnoVNC* | .{0,1000}\\EvilnoVNC.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1566.001 - T1071 - T1071.001 | TA0043 - TA0001 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 0 | N/A | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 15348 |
| 250 | *\evil-proxy.rb* | .{0,1000}\\evil\-proxy\.rb.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 15349 |
| 251 | *\evil-proxy\* | .{0,1000}\\evil\-proxy\\.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 15350 |
| 252 | *\ExtensionSpoof.exe* | .{0,1000}\\ExtensionSpoof\.exe.{0,1000} | offensive_tool_keyword | ExtensionSpoofer | Spoof file icons and extensions in Windows | T1036 - T1027.005 - T1218 | TA0005 - TA0040 | N/A | N/A | Phishing | https://github.com/henriksb/ExtensionSpoofer | 1 | 0 | N/A | N/A | 9 | 2 | 179 | 65 | 2024-12-12T18:05:28Z | 2017-11-11T16:02:17Z | 15400 |
| 253 | *\ExtensionSpoof.sln* | .{0,1000}\\ExtensionSpoof\.sln.{0,1000} | offensive_tool_keyword | ExtensionSpoofer | Spoof file icons and extensions in Windows | T1036 - T1027.005 - T1218 | TA0005 - TA0040 | N/A | N/A | Phishing | https://github.com/henriksb/ExtensionSpoofer | 1 | 0 | N/A | N/A | 9 | 2 | 179 | 65 | 2024-12-12T18:05:28Z | 2017-11-11T16:02:17Z | 15401 |
| 254 | *\ExtensionSpoofer\* | .{0,1000}\\ExtensionSpoofer\\.{0,1000} | offensive_tool_keyword | ExtensionSpoofer | Spoof file icons and extensions in Windows | T1036 - T1027.005 - T1218 | TA0005 - TA0040 | N/A | N/A | Phishing | https://github.com/henriksb/ExtensionSpoofer | 1 | 0 | N/A | N/A | 9 | 2 | 179 | 65 | 2024-12-12T18:05:28Z | 2017-11-11T16:02:17Z | 15402 |
| 255 | *\HTMLSmuggler\* | .{0,1000}\\HTMLSmuggler\\.{0,1000} | offensive_tool_keyword | HTMLSmuggler | HTML Smuggling generator&obfuscator for your Red Team operations | T1564.001 - T1027 - T1566 | TA0005 | N/A | N/A | Phishing | https://github.com/D00Movenok/HTMLSmuggler | 1 | 0 | N/A | N/A | 10 | 2 | 162 | 19 | 2024-02-27T23:03:55Z | 2023-07-02T08:10:59Z | 15834 |
| 256 | *\keygen.exe* | .{0,1000}\\keygen\.exe.{0,1000} | greyware_tool_keyword | _ | generic suspicious keyword keygen.exe observed in multiple cracked software often packed with malwares | T1204 - T1027 - T1059 - T1055 - T1060 - T1195 | TA0005 - TA0002 - TA0011 | N/A | N/A | Phishing | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 16119 |
| 257 | *\Keylogger.txt* | .{0,1000}\\Keylogger\.txt.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1566.001 - T1071 - T1071.001 | TA0043 - TA0001 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 0 | N/A | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 16129 |
| 258 | *\Lnk2Pwn.java* | .{0,1000}\\Lnk2Pwn\.java.{0,1000} | offensive_tool_keyword | lnk2pwn | Malicious Shortcut(.lnk) Generator | T1204 - T1059.007 | TA0001 - TA0002 | N/A | N/A | Phishing | https://github.com/it-gorillaz/lnk2pwn | 1 | 0 | N/A | N/A | 8 | 2 | 193 | 34 | 2018-11-23T17:18:49Z | 2018-11-23T00:12:48Z | 16304 |
| 259 | *\Lnk2PwnFrame.java* | .{0,1000}\\Lnk2PwnFrame\.java.{0,1000} | offensive_tool_keyword | lnk2pwn | Malicious Shortcut(.lnk) Generator | T1204 - T1059.007 | TA0001 - TA0002 | N/A | N/A | Phishing | https://github.com/it-gorillaz/lnk2pwn | 1 | 0 | N/A | N/A | 8 | 2 | 193 | 34 | 2018-11-23T17:18:49Z | 2018-11-23T00:12:48Z | 16305 |
| 260 | *\lnk2pwn-master* | .{0,1000}\\lnk2pwn\-master.{0,1000} | offensive_tool_keyword | lnk2pwn | Malicious Shortcut(.lnk) Generator | T1204 - T1059.007 | TA0001 - TA0002 | N/A | N/A | Phishing | https://github.com/it-gorillaz/lnk2pwn | 1 | 0 | N/A | N/A | 8 | 2 | 193 | 34 | 2018-11-23T17:18:49Z | 2018-11-23T00:12:48Z | 16306 |
| 261 | *\notavirus.exe* | .{0,1000}\\notavirus\.exe.{0,1000} | offensive_tool_keyword | tricky.lnk | VBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and execute | T1027 - T1036 - T1218.010 | TA0002 - TA0003 - TA0008 | N/A | N/A | Phishing | https://github.com/xillwillx/tricky.lnk | 1 | 0 | N/A | N/A | N/A | 2 | 114 | 33 | 2020-12-19T23:42:10Z | 2016-10-26T21:25:06Z | 16961 |
| 262 | *\PAYMENT.hta* | .{0,1000}\\PAYMENT\.hta.{0,1000} | greyware_tool_keyword | _ | suspicious file name - has been used by threat actors | T1566 | TA0001 | N/A | N/A | Phishing | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 17152 |
| 263 | *\PAYMENT.hta* | .{0,1000}\\PAYMENT\.hta.{0,1000} | greyware_tool_keyword | _ | suspicious file name - has been used by threat actors | T1566 | TA0001 | N/A | N/A | Phishing | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 17153 |
| 264 | *\PAYMENTS.exe* | .{0,1000}\\PAYMENTS\.exe.{0,1000} | greyware_tool_keyword | _ | suspicious file name - has been used by threat actors | T1566 | TA0001 | N/A | N/A | Phishing | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 17154 |
| 265 | *\phishery.exe* | .{0,1000}\\phishery\.exe.{0,1000} | offensive_tool_keyword | phishery | Phishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document. | T1566.001 - T1071 - T1204.002 | TA0001 | N/A | BERSERK BEAR | Phishing | https://github.com/ryhanson/phishery | 1 | 0 | N/A | N/A | 9 | 10 | 993 | 209 | 2017-09-11T15:42:10Z | 2016-09-25T02:19:24Z | 17240 |
| 266 | *\phishlets\example.yaml* | .{0,1000}\\phishlets\\example\.yaml.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | N/A | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 17241 |
| 267 | *\PWA-Phishing* | .{0,1000}\\PWA\-Phishing.{0,1000} | offensive_tool_keyword | PWA-Phishing | Phishing with Progressive Web Apps and UI manipulation | T1071.003 - T1204.002 - T1608.003 - T1071.004 | TA0006 | N/A | N/A | Phishing | https://github.com/mrd0x/PWA-Phishing | 1 | 0 | N/A | N/A | 10 | 3 | 288 | 52 | 2024-06-16T17:47:15Z | 2024-06-09T19:47:52Z | 17661 |
| 268 | *\recaptcha-phish-main* | .{0,1000}\\recaptcha\-phish\-main.{0,1000} | offensive_tool_keyword | recaptcha-phish | Phishing with a fake reCAPTCHA | T1566.001 - T1204.002 - T1071.003 | TA0001 - TA0002 | Lumma Stealer | N/A | Phishing | https://github.com/JohnHammond/recaptcha-phish | 1 | 0 | N/A | N/A | 10 | 6 | 534 | 104 | 2024-09-13T11:18:29Z | 2024-09-13T07:00:40Z | 17828 |
| 269 | *\smuggler.py* | .{0,1000}\\smuggler\.py.{0,1000} | offensive_tool_keyword | smuggler.py | HTML Smuggling Generator | T1564.001 - T1027 - T1566 | TA0005 | N/A | N/A | Phishing | https://github.com/infosecn1nja/red-team-scripts/blob/main/smuggler.py | 1 | 0 | N/A | N/A | 9 | 3 | 299 | 55 | 2024-08-08T06:11:06Z | 2023-01-15T22:37:34Z | 18916 |
| 270 | *\tricky.lnk\* | .{0,1000}\\tricky\.lnk\\.{0,1000} | offensive_tool_keyword | tricky.lnk | VBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and execute | T1027 - T1036 - T1218.010 | TA0002 - TA0003 - TA0008 | N/A | N/A | Phishing | https://github.com/xillwillx/tricky.lnk | 1 | 0 | N/A | N/A | N/A | 2 | 114 | 33 | 2020-12-19T23:42:10Z | 2016-10-26T21:25:06Z | 19418 |
| 271 | *\tricky.ps1* | .{0,1000}\\tricky\.ps1.{0,1000} | offensive_tool_keyword | MacroMeter | VBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and execute | T1027 - T1036 - T1218.010 | TA0002 - TA0003 - TA0008 | N/A | N/A | Phishing | https://github.com/xillwillx/tricky.lnk | 1 | 0 | N/A | N/A | N/A | 2 | 114 | 33 | 2020-12-19T23:42:10Z | 2016-10-26T21:25:06Z | 19419 |
| 272 | *\tricky.vbs* | .{0,1000}\\tricky\.vbs.{0,1000} | offensive_tool_keyword | tricky.lnk | VBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and execute | T1027 - T1036 - T1218.010 | TA0002 - TA0003 - TA0008 | N/A | N/A | Phishing | https://github.com/xillwillx/tricky.lnk | 1 | 0 | N/A | N/A | N/A | 2 | 114 | 33 | 2020-12-19T23:42:10Z | 2016-10-26T21:25:06Z | 19420 |
| 273 | *\tricky2.ps1* | .{0,1000}\\tricky2\.ps1.{0,1000} | offensive_tool_keyword | tricky.lnk | VBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and execute | T1027 - T1036 - T1218.010 | TA0002 - TA0003 - TA0008 | N/A | N/A | Phishing | https://github.com/xillwillx/tricky.lnk | 1 | 0 | N/A | N/A | N/A | 2 | 114 | 33 | 2020-12-19T23:42:10Z | 2016-10-26T21:25:06Z | 19421 |
| 274 | *\uac_bypass.vbs* | .{0,1000}\\uac_bypass\.vbs.{0,1000} | offensive_tool_keyword | lnk2pwn | Malicious Shortcut(.lnk) Generator | T1204 - T1059.007 | TA0001 - TA0002 | N/A | N/A | Phishing | https://github.com/it-gorillaz/lnk2pwn | 1 | 0 | N/A | N/A | 8 | 2 | 193 | 34 | 2018-11-23T17:18:49Z | 2018-11-23T00:12:48Z | 19465 |
| 275 | *_EvilClippy.* | .{0,1000}_EvilClippy\..{0,1000} | offensive_tool_keyword | EvilClippy | A cross-platform assistant for creating malicious MS Office documents | T1566.001 - T1059.001 - T1204.002 | TA0004 - TA0002 | N/A | N/A | Phishing | https://github.com/outflanknl/EvilClippy | 1 | 0 | N/A | N/A | 10 | 10 | 2165 | 402 | 2023-12-27T12:37:47Z | 2019-03-26T12:14:03Z | 20123 |
| 276 | *= "evil-proxy"* | .{0,1000}\=\s\"evil\-proxy\".{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 20265 |
| 277 | *=ogIXFlckIzYIRCekEHMORiIgwWY2VmCpICcahHJVRCTkcVUyRie5YFJ3RiZkAnW4RidkIzYIRiYkcHJzRCZkcVUyRyYkcHJyMGSkICIsFmdlhCJ9gnC* | .{0,1000}\=ogIXFlckIzYIRCekEHMORiIgwWY2VmCpICcahHJVRCTkcVUyRie5YFJ3RiZkAnW4RidkIzYIRiYkcHJzRCZkcVUyRyYkcHJyMGSkICIsFmdlhCJ9gnC.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 20297 | ||||
| 278 | *00895d7e0a42f794de5f471a41c0cd996ee3298a4183834cb8b99f10552a5e1c* | .{0,1000}00895d7e0a42f794de5f471a41c0cd996ee3298a4183834cb8b99f10552a5e1c.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 20669 |
| 279 | *02FAF312-BF2A-466B-8AD2-1339A31C303B* | .{0,1000}02FAF312\-BF2A\-466B\-8AD2\-1339A31C303B.{0,1000} | offensive_tool_keyword | clickjack | automate abuse of clickonce applications | T1210 - T1204 - T1071.001 | TA0001 - TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/trustedsec/The_Shelf | 1 | 0 | #GUIDproject | N/A | 10 | 3 | 247 | 14 | 2024-11-25T19:33:34Z | 2024-05-22T14:31:52Z | 20861 |
| 280 | *0675558d182096b75d100d91c77c1119d229c315f12bb86e353e49894b9e1d62* | .{0,1000}0675558d182096b75d100d91c77c1119d229c315f12bb86e353e49894b9e1d62.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 1 | N/A | N/A | N/A | N/A | 21110 |
| 281 | *0bc38984ce64aa213a77c2c9125a68a057f76f354a44060f8342d5375368ef04* | .{0,1000}0bc38984ce64aa213a77c2c9125a68a057f76f354a44060f8342d5375368ef04.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 21494 | ||||
| 282 | *10c9d70217e5a3915a6c09feea4110991dae5d9a1b6ae5d32c4d69dd6b6eaf50* | .{0,1000}10c9d70217e5a3915a6c09feea4110991dae5d9a1b6ae5d32c4d69dd6b6eaf50.{0,1000} | offensive_tool_keyword | lnk2pwn | Malicious Shortcut(.lnk) Generator | T1204 - T1059.007 | TA0001 - TA0002 | N/A | N/A | Phishing | https://github.com/it-gorillaz/lnk2pwn | 1 | 0 | #filehash | N/A | 8 | 2 | 193 | 34 | 2018-11-23T17:18:49Z | 2018-11-23T00:12:48Z | 21914 |
| 283 | *11fcbd067d55ddaa11e622be03a55ea342efe497cbcb14abf4dc410cb5d7a203* | .{0,1000}11fcbd067d55ddaa11e622be03a55ea342efe497cbcb14abf4dc410cb5d7a203.{0,1000} | offensive_tool_keyword | tricky.lnk | VBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and execute | T1027 - T1036 - T1218.010 | TA0002 - TA0003 - TA0008 | N/A | N/A | Phishing | https://github.com/xillwillx/tricky.lnk | 1 | 0 | #filehash | N/A | N/A | 2 | 114 | 33 | 2020-12-19T23:42:10Z | 2016-10-26T21:25:06Z | 22006 |
| 284 | *127.0.0.1:#{mitm_port}* | .{0,1000}127\.0\.0\.1\:\#\{mitm_port\}.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 22043 |
| 285 | *1446b2b7ac055dd73177e7610141376dcdb8419b0422f81d69c589ce60e83e42* | .{0,1000}1446b2b7ac055dd73177e7610141376dcdb8419b0422f81d69c589ce60e83e42.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 22188 |
| 286 | *16bb30509efac0ba13c42eade477ab4454c5951c1c20f7c991c62798284aa3b0* | .{0,1000}16bb30509efac0ba13c42eade477ab4454c5951c1c20f7c991c62798284aa3b0.{0,1000} | offensive_tool_keyword | phishery | Phishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document. | T1566.001 - T1071 - T1204.002 | TA0001 | N/A | BERSERK BEAR | Phishing | https://github.com/ryhanson/phishery | 1 | 0 | #filehash | N/A | 9 | 10 | 993 | 209 | 2017-09-11T15:42:10Z | 2016-09-25T02:19:24Z | 22350 |
| 287 | *1827f84465eaa41ba584561ae108be14e693ba4c992e9d58ef0148959cc9efc1* | .{0,1000}1827f84465eaa41ba584561ae108be14e693ba4c992e9d58ef0148959cc9efc1.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 22438 | ||||
| 288 | *187622b4abcd679d2a8b74ba1ea8cec9d517a4026fc58ea7c33ff13ad5c1ca88* | .{0,1000}187622b4abcd679d2a8b74ba1ea8cec9d517a4026fc58ea7c33ff13ad5c1ca88.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 22461 |
| 289 | *18c54c69f41d0b7e5928c34e1e9350ed99ecd0278ea37df11a429018ca3d05ed* | .{0,1000}18c54c69f41d0b7e5928c34e1e9350ed99ecd0278ea37df11a429018ca3d05ed.{0,1000} | offensive_tool_keyword | PWA-Phishing | Phishing with Progressive Web Apps and UI manipulation | T1071.003 - T1204.002 - T1608.003 - T1071.004 | TA0006 | N/A | N/A | Phishing | https://github.com/mrd0x/PWA-Phishing | 1 | 0 | #filehash | N/A | 10 | 3 | 288 | 52 | 2024-06-16T17:47:15Z | 2024-06-09T19:47:52Z | 22480 |
| 290 | *1a571ac5b806ffce2605b57753f74653ddb392e5afdb0e49c3e9e8d76e561568* | .{0,1000}1a571ac5b806ffce2605b57753f74653ddb392e5afdb0e49c3e9e8d76e561568.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 0 | #filehash | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 22599 |
| 291 | *1c267e901a65d142bf532bc0d26926dd9ceaa43e16b48df37c0739ba050a1c50* | .{0,1000}1c267e901a65d142bf532bc0d26926dd9ceaa43e16b48df37c0739ba050a1c50.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 22731 | ||||
| 292 | *1c7e93ed2b3eed1303cc11d09b4fea4b183fb0e7041f9584c81ca4c989d8a46f* | .{0,1000}1c7e93ed2b3eed1303cc11d09b4fea4b183fb0e7041f9584c81ca4c989d8a46f.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 22756 | ||||
| 293 | *1dd63a324303ac18c64c435bf6acfff6efa419b20c305dddb9905cde41feeb4c* | .{0,1000}1dd63a324303ac18c64c435bf6acfff6efa419b20c305dddb9905cde41feeb4c.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 22853 | ||||
| 294 | *1de0d1e7805edcd36247e2c224aa8c691c774ba8497f88f2e2dea157c30906a9* | .{0,1000}1de0d1e7805edcd36247e2c224aa8c691c774ba8497f88f2e2dea157c30906a9.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 22854 | ||||
| 295 | *1e00cb67cc7d0f6610235ae151268e1aa8c38fe8f2675f9884baf1dde23d9303* | .{0,1000}1e00cb67cc7d0f6610235ae151268e1aa8c38fe8f2675f9884baf1dde23d9303.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 22868 |
| 296 | *1f7552f9d41f1e64d15e8cface42784b169d197992a072cf0072072dc640f58d* | .{0,1000}1f7552f9d41f1e64d15e8cface42784b169d197992a072cf0072072dc640f58d.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 22986 | ||||
| 297 | *216361a2e00d7514c8300d3171dfd5cb8a5e6a061216125119a0d656d812de79* | .{0,1000}216361a2e00d7514c8300d3171dfd5cb8a5e6a061216125119a0d656d812de79.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 23132 | ||||
| 298 | *22379d69fa7ac3ae6679aba9a2346d5e66e819384641782e033f4a6efc4097c3* | .{0,1000}22379d69fa7ac3ae6679aba9a2346d5e66e819384641782e033f4a6efc4097c3.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 23198 | ||||
| 299 | *2443660c8c3e8fcf80e028c6417a0110fde1f3a0961f70ffb960cbf64958e244* | .{0,1000}2443660c8c3e8fcf80e028c6417a0110fde1f3a0961f70ffb960cbf64958e244.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 23341 | ||||
| 300 | *2609239cc8bc517f684285133622e8b11192fb456e2dc2937aa2c6c2379a9d38* | .{0,1000}2609239cc8bc517f684285133622e8b11192fb456e2dc2937aa2c6c2379a9d38.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 23460 | ||||
| 301 | *2711dda772bc1073c031d6044b5fe5eddc6943420ebd7e214e0b5e60adcd89d6* | .{0,1000}2711dda772bc1073c031d6044b5fe5eddc6943420ebd7e214e0b5e60adcd89d6.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 23541 | ||||
| 302 | *298047e6ce299b73ea411a8ed2d67484db6c8c276a299403e0b9766cc9079456* | .{0,1000}298047e6ce299b73ea411a8ed2d67484db6c8c276a299403e0b9766cc9079456.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 23696 | ||||
| 303 | *2d3ce0b49997314a863aa4a9ef25fe06021aac1107aaf63af18ba9730f13e7e3* | .{0,1000}2d3ce0b49997314a863aa4a9ef25fe06021aac1107aaf63af18ba9730f13e7e3.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 23929 | ||||
| 304 | *2f2673bba488dc6bfd8e64f2d9b14049a4b495b7149a2e16980547467afc3fba* | .{0,1000}2f2673bba488dc6bfd8e64f2d9b14049a4b495b7149a2e16980547467afc3fba.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 24079 | ||||
| 305 | *31795b2f772b6ad00274cc4eb40aaf81b5d38d6eeae56bace80a07bbb1aeac35* | .{0,1000}31795b2f772b6ad00274cc4eb40aaf81b5d38d6eeae56bace80a07bbb1aeac35.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 24262 | ||||
| 306 | *334a8657b76c88f5d7b6a2be78cc4e9e6c5ecaeea5a104cea5e6d0c4250674a7* | .{0,1000}334a8657b76c88f5d7b6a2be78cc4e9e6c5ecaeea5a104cea5e6d0c4250674a7.{0,1000} | offensive_tool_keyword | phishery | Phishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document. | T1566.001 - T1071 - T1204.002 | TA0001 | N/A | BERSERK BEAR | Phishing | https://github.com/ryhanson/phishery | 1 | 0 | #filehash | N/A | 9 | 10 | 993 | 209 | 2017-09-11T15:42:10Z | 2016-09-25T02:19:24Z | 24387 |
| 307 | *335ac01e952db33997b844a2e7c506d541e353d6e82ead3fde51e4879fde736a* | .{0,1000}335ac01e952db33997b844a2e7c506d541e353d6e82ead3fde51e4879fde736a.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 24394 | ||||
| 308 | *365-Stealer.py* | .{0,1000}365\-Stealer\.py.{0,1000} | offensive_tool_keyword | 365-Stealer | 365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack | T1111 - T1566.001 - T1078.004 | TA0004 - TA0001 - TA0040 | N/A | N/A | Phishing | https://github.com/AlteredSecurity/365-Stealer | 1 | 1 | N/A | N/A | 10 | 5 | 488 | 89 | 2024-06-08T21:03:50Z | 2020-09-20T18:22:36Z | 24596 |
| 309 | *365-Stealer-master* | .{0,1000}365\-Stealer\-master.{0,1000} | offensive_tool_keyword | 365-Stealer | 365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack | T1111 - T1566.001 - T1078.004 | TA0004 - TA0001 - TA0040 | N/A | N/A | Phishing | https://github.com/AlteredSecurity/365-Stealer | 1 | 1 | N/A | N/A | 10 | 5 | 488 | 89 | 2024-06-08T21:03:50Z | 2020-09-20T18:22:36Z | 24597 |
| 310 | *36ff05fc406bf6a2e677374028ba00cb622b2219e44c198d5dd6efae4ae963c3* | .{0,1000}36ff05fc406bf6a2e677374028ba00cb622b2219e44c198d5dd6efae4ae963c3.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 0 | N/A | N/A | 10 | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 24648 |
| 311 | *3a3bd44b20afbb14ce14e70e474491383c2fcc87a554e4fbdc489c65ee7ace2a* | .{0,1000}3a3bd44b20afbb14ce14e70e474491383c2fcc87a554e4fbdc489c65ee7ace2a.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 24881 | ||||
| 312 | *3b1e2b01bfa6ad0deefa3bf8e7a81e9fc295e56b8f087ef402d9a06e42ec3b95* | .{0,1000}3b1e2b01bfa6ad0deefa3bf8e7a81e9fc295e56b8f087ef402d9a06e42ec3b95.{0,1000} | offensive_tool_keyword | PWA-Phishing | Phishing with Progressive Web Apps and UI manipulation | T1071.003 - T1204.002 - T1608.003 - T1071.004 | TA0006 | N/A | N/A | Phishing | https://github.com/mrd0x/PWA-Phishing | 1 | 0 | #filehash | N/A | 10 | 3 | 288 | 52 | 2024-06-16T17:47:15Z | 2024-06-09T19:47:52Z | 24939 |
| 313 | *3b3fd00d44c44dbb8387dcd1b41772fb3fdd14b15d24d2af981d9da783545b68* | .{0,1000}3b3fd00d44c44dbb8387dcd1b41772fb3fdd14b15d24d2af981d9da783545b68.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 24945 |
| 314 | *3ba7ec45c5017f57077a98ed61ce1f24dacddfb4928c20351aba2c0ae4398e39* | .{0,1000}3ba7ec45c5017f57077a98ed61ce1f24dacddfb4928c20351aba2c0ae4398e39.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 24972 |
| 315 | *3ccb81e184f94e47a9a7c7e75978ad9eda2850967b0a2e03a505776e4969b8a2* | .{0,1000}3ccb81e184f94e47a9a7c7e75978ad9eda2850967b0a2e03a505776e4969b8a2.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 25056 | ||||
| 316 | *3d27ba8268164db337978538c6e6c33e0b91194d184e6b6b73f1089a425a60f5* | .{0,1000}3d27ba8268164db337978538c6e6c33e0b91194d184e6b6b73f1089a425a60f5.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 25080 | ||||
| 317 | *3e3b34ad2eaa319676168ff54b63f3219c517cbd50c3df43b2fb4cfe141b5ab2* | .{0,1000}3e3b34ad2eaa319676168ff54b63f3219c517cbd50c3df43b2fb4cfe141b5ab2.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 25141 |
| 318 | *3xploitGuy/pastehakk* | .{0,1000}3xploitGuy\/pastehakk.{0,1000} | offensive_tool_keyword | pastehakk | perform clipboard poisoning or paste jacking attack | T1115 | T0001 - T0002 - T0005 | N/A | N/A | Phishing | https://github.com/3xploitGuy/pastehakk | 1 | 1 | N/A | N/A | 7 | 1 | 56 | 10 | 2020-06-22T01:17:53Z | 2020-06-17T19:32:24Z | 25300 |
| 319 | *40e8b756d0f996d7127ffc76d3fb122dd014455bc6b0c007e6d5d77e5bb6211b* | .{0,1000}40e8b756d0f996d7127ffc76d3fb122dd014455bc6b0c007e6d5d77e5bb6211b.{0,1000} | offensive_tool_keyword | clickjack | automate abuse of clickonce applications | T1210 - T1204 - T1071.001 | TA0001 - TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/trustedsec/The_Shelf | 1 | 0 | #filehash | N/A | 10 | 3 | 247 | 14 | 2024-11-25T19:33:34Z | 2024-05-22T14:31:52Z | 25372 |
| 320 | *43bc3fe471a81b11c2e59cd0fd55630cee7860f8caad44fb8ee54d109e01a5e5* | .{0,1000}43bc3fe471a81b11c2e59cd0fd55630cee7860f8caad44fb8ee54d109e01a5e5.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 25595 | ||||
| 321 | *4614a6da343623fc820d89d35b8c2a26fe69abf357af7ef7602e52808fbe8611* | .{0,1000}4614a6da343623fc820d89d35b8c2a26fe69abf357af7ef7602e52808fbe8611.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 25760 | ||||
| 322 | *4aa27ae37edfbfe57f3ab989d192caf21b3c871516958eb77205c9ad700c3f67* | .{0,1000}4aa27ae37edfbfe57f3ab989d192caf21b3c871516958eb77205c9ad700c3f67.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 26059 | ||||
| 323 | *4f2678fa0f90074ae304f8fdb9174d0c577f1a0587af44a4e8e756a547e5c2e4* | .{0,1000}4f2678fa0f90074ae304f8fdb9174d0c577f1a0587af44a4e8e756a547e5c2e4.{0,1000} | offensive_tool_keyword | recaptcha-phish | Phishing with a fake reCAPTCHA | T1566.001 - T1204.002 - T1071.003 | TA0001 - TA0002 | Lumma Stealer | N/A | Phishing | https://github.com/JohnHammond/recaptcha-phish | 1 | 0 | #filehash | N/A | 10 | 6 | 534 | 104 | 2024-09-13T11:18:29Z | 2024-09-13T07:00:40Z | 26411 |
| 324 | *520f529151f419ccb0e75d9f9d2c9a24fb4809468dbd95360e4483672db46407* | .{0,1000}520f529151f419ccb0e75d9f9d2c9a24fb4809468dbd95360e4483672db46407.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 26646 | ||||
| 325 | *52b1b3fa12706c1cc7ca2da321e23b151f812a5f7660f0114cc8470de3a3065d* | .{0,1000}52b1b3fa12706c1cc7ca2da321e23b151f812a5f7660f0114cc8470de3a3065d.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 26683 | ||||
| 326 | *53a9c6eed3ee5ed0ea6fe900bbcdac2b9c0709c57c8d82688ef32f7e2b784f60* | .{0,1000}53a9c6eed3ee5ed0ea6fe900bbcdac2b9c0709c57c8d82688ef32f7e2b784f60.{0,1000} | offensive_tool_keyword | pastehakk | perform clipboard poisoning or paste jacking attack | T1115 | T0001 - T0002 - T0005 | N/A | N/A | Phishing | https://github.com/3xploitGuy/pastehakk | 1 | 0 | #linux #filehash | N/A | 7 | 1 | 56 | 10 | 2020-06-22T01:17:53Z | 2020-06-17T19:32:24Z | 26744 |
| 327 | *5406c993ef16ac875804185a8f37db5b2473def489a613de0b667f304b498c97* | .{0,1000}5406c993ef16ac875804185a8f37db5b2473def489a613de0b667f304b498c97.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 26769 |
| 328 | *55049f7690abbbb5c8dc844e54b63269d111c0cd21e98854c666a27788dc5de6* | .{0,1000}55049f7690abbbb5c8dc844e54b63269d111c0cd21e98854c666a27788dc5de6.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 26848 | ||||
| 329 | *55a3bbb8a62578b455e478cb197aadd389f2e65418595e5df4636972be878710* | .{0,1000}55a3bbb8a62578b455e478cb197aadd389f2e65418595e5df4636972be878710.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 26895 | ||||
| 330 | *5740d6067561fcd27239374abbfd7076d3df5909b107a32bbb2e9eec0e9f4d61* | .{0,1000}5740d6067561fcd27239374abbfd7076d3df5909b107a32bbb2e9eec0e9f4d61.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 27027 | ||||
| 331 | *57630a0b38ad185ff8a8d0706ff9cebfd12f47526ceeeb90cc3a17e124316fe2* | .{0,1000}57630a0b38ad185ff8a8d0706ff9cebfd12f47526ceeeb90cc3a17e124316fe2.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 27040 | ||||
| 332 | *57f5a53203d19daa9bb094b442bc029a374686af5be71741e5536e35590e9f9c* | .{0,1000}57f5a53203d19daa9bb094b442bc029a374686af5be71741e5536e35590e9f9c.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 27083 | ||||
| 333 | *595a77ddfb6f674bd5bc1c297ae912f5ebf6ba218a2f857ff46b7b37d1a9678b* | .{0,1000}595a77ddfb6f674bd5bc1c297ae912f5ebf6ba218a2f857ff46b7b37d1a9678b.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 27188 |
| 334 | *5a2845a19dc310535eec5c74dd770db258e90160ea63e5cc9d97ab87de8081ff* | .{0,1000}5a2845a19dc310535eec5c74dd770db258e90160ea63e5cc9d97ab87de8081ff.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 27235 | ||||
| 335 | *5a3ae8d1bf88a4415c293623ca868e718bf2addbfc88953267bed9c9cf57c2ad* | .{0,1000}5a3ae8d1bf88a4415c293623ca868e718bf2addbfc88953267bed9c9cf57c2ad.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 27239 | ||||
| 336 | *5ae17ceeb8dcfb5eb56fc27876c5047ddfebcb9114beb0a03db81000c46d7054* | .{0,1000}5ae17ceeb8dcfb5eb56fc27876c5047ddfebcb9114beb0a03db81000c46d7054.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 27280 | ||||
| 337 | *5c5bd260c00111edc55b4bc8a82d72e0a510f738ce3696ab2bbcd4a38a84bb12* | .{0,1000}5c5bd260c00111edc55b4bc8a82d72e0a510f738ce3696ab2bbcd4a38a84bb12.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 27415 | ||||
| 338 | *5c78c058c8278438ce30b86b3ccda222410206ec0ea5727b93b74bb8c6748bd5* | .{0,1000}5c78c058c8278438ce30b86b3ccda222410206ec0ea5727b93b74bb8c6748bd5.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 27423 | ||||
| 339 | *5d447208b1a06d45b5563f56da869e3c6ffa8e67247809798d24065d719160e8* | .{0,1000}5d447208b1a06d45b5563f56da869e3c6ffa8e67247809798d24065d719160e8.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 27495 | ||||
| 340 | *5d494fc79356aeb1e983aab7188e729550c1f54ffcdcb02270acc492f2164afa* | .{0,1000}5d494fc79356aeb1e983aab7188e729550c1f54ffcdcb02270acc492f2164afa.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 27497 | ||||
| 341 | *5d848352fb3ae2109dd1ee927717c8c004f2e07f33b14d7fd25dba71784f5579* | .{0,1000}5d848352fb3ae2109dd1ee927717c8c004f2e07f33b14d7fd25dba71784f5579.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 27508 | ||||
| 342 | *5ebd789e726c94beb41e0934df6fb9bf62af28cc87093b9785dc9baa4ecde96b* | .{0,1000}5ebd789e726c94beb41e0934df6fb9bf62af28cc87093b9785dc9baa4ecde96b.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 27600 | ||||
| 343 | *613e5ca15d9bab3a0bad0c5eb8d63894c1b9fbab924385296c29d3b4f3479ee3* | .{0,1000}613e5ca15d9bab3a0bad0c5eb8d63894c1b9fbab924385296c29d3b4f3479ee3.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 27757 | ||||
| 344 | *62eb5977f66221339e954ea9e4947966ad4558966264814a406b93dab8b275df* | .{0,1000}62eb5977f66221339e954ea9e4947966ad4558966264814a406b93dab8b275df.{0,1000} | offensive_tool_keyword | EvilClippy | A cross-platform assistant for creating malicious MS Office documents | T1566.001 - T1059.001 - T1204.002 | TA0004 - TA0002 | N/A | N/A | Phishing | https://github.com/outflanknl/EvilClippy | 1 | 0 | #filehash | N/A | 10 | 10 | 2165 | 402 | 2023-12-27T12:37:47Z | 2019-03-26T12:14:03Z | 27870 |
| 345 | *64591a6674fa71f5bf6858e009d487a56dc13d306cdab14a76e7b6fe49d4338b* | .{0,1000}64591a6674fa71f5bf6858e009d487a56dc13d306cdab14a76e7b6fe49d4338b.{0,1000} | offensive_tool_keyword | phishery | Phishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document. | T1566.001 - T1071 - T1204.002 | TA0001 | N/A | BERSERK BEAR | Phishing | https://github.com/ryhanson/phishery | 1 | 0 | #filehash | N/A | 9 | 10 | 993 | 209 | 2017-09-11T15:42:10Z | 2016-09-25T02:19:24Z | 27978 |
| 346 | *64853db4da2d13a82c795e1eb6e7e2c4efc2d673be34b5f65398f54b7277a5de* | .{0,1000}64853db4da2d13a82c795e1eb6e7e2c4efc2d673be34b5f65398f54b7277a5de.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 27987 | ||||
| 347 | *6522659bfa7046803bb28a749799fb9b876d656fa46037fe28709fb4ad15d115* | .{0,1000}6522659bfa7046803bb28a749799fb9b876d656fa46037fe28709fb4ad15d115.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 28035 | ||||
| 348 | *652c0669b041362a1ece950a33752cca4940146934d651c04f992b8f11b0fba0* | .{0,1000}652c0669b041362a1ece950a33752cca4940146934d651c04f992b8f11b0fba0.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 28036 |
| 349 | *6555c9310f7087fcf0b38eab5ad4efc6ec91566ff5bf2fbbed4e63c88611c395* | .{0,1000}6555c9310f7087fcf0b38eab5ad4efc6ec91566ff5bf2fbbed4e63c88611c395.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 28043 | ||||
| 350 | *65696f93bce6d78c8e377fc3c4c56123f49f26a621a332bc764c274aa7c81632* | .{0,1000}65696f93bce6d78c8e377fc3c4c56123f49f26a621a332bc764c274aa7c81632.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 28048 | ||||
| 351 | *676766b4b6296303a601cf2191da028cc39681fa69b1da408242882f760c849b* | .{0,1000}676766b4b6296303a601cf2191da028cc39681fa69b1da408242882f760c849b.{0,1000} | offensive_tool_keyword | tricky.lnk | VBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and execute | T1027 - T1036 - T1218.010 | TA0002 - TA0003 - TA0008 | N/A | N/A | Phishing | https://github.com/xillwillx/tricky.lnk | 1 | 0 | #filehash | N/A | N/A | 2 | 114 | 33 | 2020-12-19T23:42:10Z | 2016-10-26T21:25:06Z | 28181 |
| 352 | *67831df0ff8ed3ffacc3678a5c4c09a3fcb755ffbfc110d6f1ff61fe65f31d28* | .{0,1000}67831df0ff8ed3ffacc3678a5c4c09a3fcb755ffbfc110d6f1ff61fe65f31d28.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 28186 | ||||
| 353 | *69ee333eaf49be76d5bde1d3abfbd2e9a006a316284394e92aa71db1970d927d* | .{0,1000}69ee333eaf49be76d5bde1d3abfbd2e9a006a316284394e92aa71db1970d927d.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 28331 | ||||
| 354 | *6a5607a6886ad393bd1926b90a6364fb8b6546ad6963f42571c609279b446faa* | .{0,1000}6a5607a6886ad393bd1926b90a6364fb8b6546ad6963f42571c609279b446faa.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 28362 | ||||
| 355 | *6e9cafc470be9e0db016266a1e663e39d0c764649629a6d0e28c18f103b67a43* | .{0,1000}6e9cafc470be9e0db016266a1e663e39d0c764649629a6d0e28c18f103b67a43.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 28625 |
| 356 | *7076e114583006ebcf8f50ab7540ce8552af788431ef2a89227e74876dd13e17* | .{0,1000}7076e114583006ebcf8f50ab7540ce8552af788431ef2a89227e74876dd13e17.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 28763 | ||||
| 357 | *7148724805f706f8da206b24e03f2f6381bb9bc6959bbf51b6414ea8903caddd* | .{0,1000}7148724805f706f8da206b24e03f2f6381bb9bc6959bbf51b6414ea8903caddd.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 28822 | ||||
| 358 | *72af248c9e2b92add20bde3532f73569fe2c3e941fd12c72f13696f6ccd60813* | .{0,1000}72af248c9e2b92add20bde3532f73569fe2c3e941fd12c72f13696f6ccd60813.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 28921 | ||||
| 359 | *72dcd04c582db154eee02cde9a14312542b86615a88bf47d6529b26f8c87914c* | .{0,1000}72dcd04c582db154eee02cde9a14312542b86615a88bf47d6529b26f8c87914c.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 28938 | ||||
| 360 | *75d0adaef55ce5b4670e7634d3f440e9d7e0eb1e04cb98c3919d0ad66dffbdfe* | .{0,1000}75d0adaef55ce5b4670e7634d3f440e9d7e0eb1e04cb98c3919d0ad66dffbdfe.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 29133 | ||||
| 361 | *7612416d8bde145810923ed8f75d2c1fb81cdecc1aa7a997ae68cffb5dc99f43* | .{0,1000}7612416d8bde145810923ed8f75d2c1fb81cdecc1aa7a997ae68cffb5dc99f43.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 29152 | ||||
| 362 | *7760d7ef318933db6b09dba08ec12ddf25ead0512c45bd914256c97470c4eb29* | .{0,1000}7760d7ef318933db6b09dba08ec12ddf25ead0512c45bd914256c97470c4eb29.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 29239 | ||||
| 363 | *79816edc41cd5e2aeb19f0227e9cb9ab0b5abcc54931c6bf29813f8762828805* | .{0,1000}79816edc41cd5e2aeb19f0227e9cb9ab0b5abcc54931c6bf29813f8762828805.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 29396 | ||||
| 364 | *7a6baa66cbbfa32e37a003017e6a24ae5ba2764f39039a56d7556f2931824e49* | .{0,1000}7a6baa66cbbfa32e37a003017e6a24ae5ba2764f39039a56d7556f2931824e49.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 29466 | ||||
| 365 | *7bc9e0e60db343690d6dcb61dd7f19c69fbd154234cbc38f7631f4a4a75fca8c* | .{0,1000}7bc9e0e60db343690d6dcb61dd7f19c69fbd154234cbc38f7631f4a4a75fca8c.{0,1000} | offensive_tool_keyword | lnk2pwn | Malicious Shortcut(.lnk) Generator | T1204 - T1059.007 | TA0001 - TA0002 | N/A | N/A | Phishing | https://github.com/it-gorillaz/lnk2pwn | 1 | 0 | #filehash | N/A | 8 | 2 | 193 | 34 | 2018-11-23T17:18:49Z | 2018-11-23T00:12:48Z | 29560 |
| 366 | *7ce9ff1b4f75bf4289a2f1a1c33bef9719109712019989d28c14b51703b973fc* | .{0,1000}7ce9ff1b4f75bf4289a2f1a1c33bef9719109712019989d28c14b51703b973fc.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 29648 | ||||
| 367 | *7fcc036a7fba571b7f2928f0a6a0e0838cb9e1a2a8231f9c30ce5baa144e8108* | .{0,1000}7fcc036a7fba571b7f2928f0a6a0e0838cb9e1a2a8231f9c30ce5baa144e8108.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 29845 | ||||
| 368 | *80 253 149 118 169 176 183 169 182 184* | .{0,1000}80\s253\s149\s118\s169\s176\s183\s169\s182\s184.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #content | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 29868 |
| 369 | *809f540f580fc0e192a1c0432ec04105a3faf51f9d7c20f5e15423b78774052d* | .{0,1000}809f540f580fc0e192a1c0432ec04105a3faf51f9d7c20f5e15423b78774052d.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 0 | N/A | N/A | 10 | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 29924 |
| 370 | *80e5d08cc3b73bf1c8e1b9ad7280936bb8d83f0a41f6fdd277e19511e3340cf6* | .{0,1000}80e5d08cc3b73bf1c8e1b9ad7280936bb8d83f0a41f6fdd277e19511e3340cf6.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 29944 | ||||
| 371 | *81c02fac6308e64ef8eba1bf4088b04daf1d33ac295c9a376b31e616cd3d4cec* | .{0,1000}81c02fac6308e64ef8eba1bf4088b04daf1d33ac295c9a376b31e616cd3d4cec.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 30001 | ||||
| 372 | *821a3a1dee846b299275f7cc29f51b3d20c651db082832b904ea15f8a73ad9bb* | .{0,1000}821a3a1dee846b299275f7cc29f51b3d20c651db082832b904ea15f8a73ad9bb.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 30028 |
| 373 | *823c3d2bbca46e7aedadfef6893babcbf14b0182e598a9ba958b84892daaeeb1* | .{0,1000}823c3d2bbca46e7aedadfef6893babcbf14b0182e598a9ba958b84892daaeeb1.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 30037 | ||||
| 374 | *88113ededbda181be6c6f9bd4ba8145666b48bf9e9b8dc170e66e884b10fdc91* | .{0,1000}88113ededbda181be6c6f9bd4ba8145666b48bf9e9b8dc170e66e884b10fdc91.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 30429 | ||||
| 375 | *88f333f2f21ca05e44a91c376022997c2bbec79b9d9982d59ee6d38183df86f3* | .{0,1000}88f333f2f21ca05e44a91c376022997c2bbec79b9d9982d59ee6d38183df86f3.{0,1000} | offensive_tool_keyword | clickjack | automate abuse of clickonce applications | T1210 - T1204 - T1071.001 | TA0001 - TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/trustedsec/The_Shelf | 1 | 0 | #filehash | N/A | 10 | 3 | 247 | 14 | 2024-11-25T19:33:34Z | 2024-05-22T14:31:52Z | 30499 |
| 376 | *8a65c348023a1a5555beb0cde66891fd39dcbd8e6fc02c1ce2022ac2afe68a5e* | .{0,1000}8a65c348023a1a5555beb0cde66891fd39dcbd8e6fc02c1ce2022ac2afe68a5e.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 30611 | ||||
| 377 | *8aac7bb51d605351a79f988d1b1772ae94d4b8ab4622118259effad125719e99* | .{0,1000}8aac7bb51d605351a79f988d1b1772ae94d4b8ab4622118259effad125719e99.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 30619 | ||||
| 378 | *8d1f3e17106324aad99a98f5dd921db9d27a620b37cadc06a4c470f4404dfca2* | .{0,1000}8d1f3e17106324aad99a98f5dd921db9d27a620b37cadc06a4c470f4404dfca2.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 30806 | ||||
| 379 | *8fa8dcae188d04bb3bb48782d5f97019c3a122816d9f48a6a8554ce211acb1f8* | .{0,1000}8fa8dcae188d04bb3bb48782d5f97019c3a122816d9f48a6a8554ce211acb1f8.{0,1000} | offensive_tool_keyword | phishery | Phishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document. | T1566.001 - T1071 - T1204.002 | TA0001 | N/A | BERSERK BEAR | Phishing | https://github.com/ryhanson/phishery | 1 | 0 | #filehash | N/A | 9 | 10 | 993 | 209 | 2017-09-11T15:42:10Z | 2016-09-25T02:19:24Z | 30989 |
| 380 | *91b1c7537e69ff7ade05c1c3a6051c2981a022a11b71c6e355891e294574a066* | .{0,1000}91b1c7537e69ff7ade05c1c3a6051c2981a022a11b71c6e355891e294574a066.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 31136 | ||||
| 381 | *91f2f27015c46a8de16a364b3c2455dc2cbf43a7b678141d907660f26c3d3f69* | .{0,1000}91f2f27015c46a8de16a364b3c2455dc2cbf43a7b678141d907660f26c3d3f69.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 31152 |
| 382 | *945efb5ef7d46cf1e4f5383fb158ea5cd63d42214ea44abd73592f6ceeb6cf33* | .{0,1000}945efb5ef7d46cf1e4f5383fb158ea5cd63d42214ea44abd73592f6ceeb6cf33.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 31318 | ||||
| 383 | *94aaedf468e4187388ab53a01bfdd820a47ebc3a78e2404285c040ccfea9161f* | .{0,1000}94aaedf468e4187388ab53a01bfdd820a47ebc3a78e2404285c040ccfea9161f.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 31334 |
| 384 | *9593cc106f75cc415faadbeb5b16fa79cfe8c047ad007d50dbf8cb1d242126de* | .{0,1000}9593cc106f75cc415faadbeb5b16fa79cfe8c047ad007d50dbf8cb1d242126de.{0,1000} | offensive_tool_keyword | recaptcha-phish | Phishing with a fake reCAPTCHA | T1566.001 - T1204.002 - T1071.003 | TA0001 - TA0002 | Lumma Stealer | N/A | Phishing | https://github.com/JohnHammond/recaptcha-phish | 1 | 0 | #filehash | N/A | 10 | 6 | 534 | 104 | 2024-09-13T11:18:29Z | 2024-09-13T07:00:40Z | 31411 |
| 385 | *95b9a6d12b978a6c1bbd6a33369e39008e7d64544d50c98c9c3f2b93a9466e79* | .{0,1000}95b9a6d12b978a6c1bbd6a33369e39008e7d64544d50c98c9c3f2b93a9466e79.{0,1000} | offensive_tool_keyword | PWA-Phishing | Phishing with Progressive Web Apps and UI manipulation | T1071.003 - T1204.002 - T1608.003 - T1071.004 | TA0006 | N/A | N/A | Phishing | https://github.com/mrd0x/PWA-Phishing | 1 | 0 | #filehash | N/A | 10 | 3 | 288 | 52 | 2024-06-16T17:47:15Z | 2024-06-09T19:47:52Z | 31420 |
| 386 | *9748cdfecb95fd7bb1706a566e79d3fccb1418bbb4307f7a7a1de1809db83afe* | .{0,1000}9748cdfecb95fd7bb1706a566e79d3fccb1418bbb4307f7a7a1de1809db83afe.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 31522 | ||||
| 387 | *97499fbdae8e2c952f21da5834caf06b11dcc28d74b034b509bd174f3d1f1739* | .{0,1000}97499fbdae8e2c952f21da5834caf06b11dcc28d74b034b509bd174f3d1f1739.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 31523 | ||||
| 388 | *97e7f134cfbb11e0e3ade71cdb5de36ea8cfdffe5272ea7293e35bd2b91f3449* | .{0,1000}97e7f134cfbb11e0e3ade71cdb5de36ea8cfdffe5272ea7293e35bd2b91f3449.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 31558 | ||||
| 389 | *98aa8eec1bda59ea57693a6312bae2b76b2e71dd29cd0f85453c3d867ec69394* | .{0,1000}98aa8eec1bda59ea57693a6312bae2b76b2e71dd29cd0f85453c3d867ec69394.{0,1000} | offensive_tool_keyword | lnk2pwn | Malicious Shortcut(.lnk) Generator | T1204 - T1059.007 | TA0001 - TA0002 | N/A | N/A | Phishing | https://github.com/it-gorillaz/lnk2pwn | 1 | 0 | #filehash | N/A | 8 | 2 | 193 | 34 | 2018-11-23T17:18:49Z | 2018-11-23T00:12:48Z | 31610 |
| 390 | *98fa9af535fd48260a65e18ceb9553187786742c6c77486bb27e5fe61758ea77* | .{0,1000}98fa9af535fd48260a65e18ceb9553187786742c6c77486bb27e5fe61758ea77.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 31628 | ||||
| 391 | *9c9cc73f47b3b509df0845593e6b2f8d900f34772e4aaf3438bb0120303d5670* | .{0,1000}9c9cc73f47b3b509df0845593e6b2f8d900f34772e4aaf3438bb0120303d5670.{0,1000} | offensive_tool_keyword | tricky.lnk | VBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and execute | T1027 - T1036 - T1218.010 | TA0002 - TA0003 - TA0008 | N/A | N/A | Phishing | https://github.com/xillwillx/tricky.lnk | 1 | 0 | #filehash | N/A | N/A | 2 | 114 | 33 | 2020-12-19T23:42:10Z | 2016-10-26T21:25:06Z | 31881 |
| 392 | *9d571b529b8c97f1d95d00147a98ca6a208446100108993377ef74f7bfab0ced* | .{0,1000}9d571b529b8c97f1d95d00147a98ca6a208446100108993377ef74f7bfab0ced.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 31937 | ||||
| 393 | *9e83b2e2efe2a751a735f413dee7582e8ba8a0639b8d092cf165b87b166639c2* | .{0,1000}9e83b2e2efe2a751a735f413dee7582e8ba8a0639b8d092cf165b87b166639c2.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 32007 |
| 394 | *A ruby http/https proxy to do EVIL things.* | .{0,1000}A\sruby\shttp\/https\sproxy\sto\sdo\sEVIL\sthings\..{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 32134 |
| 395 | *a16a8ed5999b3b90c7f5a7a80b7a55fe62941d3a1300ea8f0fcdd8550e93a947* | .{0,1000}a16a8ed5999b3b90c7f5a7a80b7a55fe62941d3a1300ea8f0fcdd8550e93a947.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 32245 | ||||
| 396 | *a2b03c173484ada281f36aeabeedc6ced6d4289d4c204aa69b8a65c3f45037db* | .{0,1000}a2b03c173484ada281f36aeabeedc6ced6d4289d4c204aa69b8a65c3f45037db.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 32346 |
| 397 | *a760cde750a65dd7e7ea970c57f662c91c7614d33d69b4720ea630db4961ff1e* | .{0,1000}a760cde750a65dd7e7ea970c57f662c91c7614d33d69b4720ea630db4961ff1e.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 32678 |
| 398 | *a7a5c912263b0207145bd9c2397a4fa338ec82217df2ab83471bb884e473cc9e* | .{0,1000}a7a5c912263b0207145bd9c2397a4fa338ec82217df2ab83471bb884e473cc9e.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 32698 | ||||
| 399 | *aa14822e2f2acd7b8aff1ebf1f2e7e9f800f6089f868ec7464af6ac01d7f9b3c* | .{0,1000}aa14822e2f2acd7b8aff1ebf1f2e7e9f800f6089f868ec7464af6ac01d7f9b3c.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 32880 | ||||
| 400 | *aa5838415ca20f0b6fe7858f457f129cf442940b3d4676cd243575809e53988e* | .{0,1000}aa5838415ca20f0b6fe7858f457f129cf442940b3d4676cd243575809e53988e.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 32892 | ||||
| 401 | *ac03d370bbdfc9037c1dfb4fc9a4fc5a3914acb58e082a33fc5c52bdbc8768f4* | .{0,1000}ac03d370bbdfc9037c1dfb4fc9a4fc5a3914acb58e082a33fc5c52bdbc8768f4.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 33051 |
| 402 | *aeebbc6ea13dde53ffa47ec90eb80c571c81da63e36f2c8539a9924f54933a09* | .{0,1000}aeebbc6ea13dde53ffa47ec90eb80c571c81da63e36f2c8539a9924f54933a09.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 33582 | ||||
| 403 | *afd28d12d55e823076544802e23776a6150aa3095f8c9b5904cf35af8d258186* | .{0,1000}afd28d12d55e823076544802e23776a6150aa3095f8c9b5904cf35af8d258186.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 33660 |
| 404 | *AlteredSecurity/365-Stealer* | .{0,1000}AlteredSecurity\/365\-Stealer.{0,1000} | offensive_tool_keyword | 365-Stealer | 365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack | T1111 - T1566.001 - T1078.004 | TA0004 - TA0001 - TA0040 | N/A | N/A | Phishing | https://github.com/AlteredSecurity/365-Stealer | 1 | 1 | N/A | N/A | 10 | 5 | 488 | 89 | 2024-06-08T21:03:50Z | 2020-09-20T18:22:36Z | 33822 |
| 405 | *An0nUD4Y/Evilginx2-Phishlets* | .{0,1000}An0nUD4Y\/Evilginx2\-Phishlets.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/Evilginx2-Phishlets | 1 | 0 | N/A | N/A | 10 | 7 | 670 | 263 | 2025-02-06T02:46:16Z | 2020-05-13T05:58:43Z | 33867 |
| 406 | *Arno0x/EmbedInHTML* | .{0,1000}Arno0x\/EmbedInHTML.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 1 | N/A | N/A | N/A | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 34066 |
| 407 | *AttackerSetup(windows).exe* | .{0,1000}AttackerSetup\(windows\)\.exe.{0,1000} | offensive_tool_keyword | windows-login-phish | Windows Login Phishing page This is a windows maching login page designed using HTML CSS and JS. This can be used for red teaming or cybersecurity awareness related purposes | T1566 | N/A | N/A | N/A | Phishing | https://github.com/CipherKill/windows-login-phish | 1 | 1 | N/A | N/A | N/A | 1 | 17 | 6 | 2022-03-25T05:49:01Z | 2022-03-13T20:02:15Z | 34224 |
| 408 | *AttackerSetup.py* | .{0,1000}AttackerSetup\.py.{0,1000} | offensive_tool_keyword | windows-login-phish | Windows Login Phishing page This is a windows maching login page designed using HTML CSS and JS. This can be used for red teaming or cybersecurity awareness related purposes | T1566 | N/A | N/A | N/A | Phishing | https://github.com/CipherKill/windows-login-phish | 1 | 1 | N/A | N/A | N/A | 1 | 17 | 6 | 2022-03-25T05:49:01Z | 2022-03-13T20:02:15Z | 34225 |
| 409 | *AttackerSetup4linux* | .{0,1000}AttackerSetup4linux.{0,1000} | offensive_tool_keyword | windows-login-phish | Windows Login Phishing page This is a windows maching login page designed using HTML CSS and JS. This can be used for red teaming or cybersecurity awareness related purposes | T1566 | N/A | N/A | N/A | Phishing | https://github.com/CipherKill/windows-login-phish | 1 | 1 | #linux | N/A | N/A | 1 | 17 | 6 | 2022-03-25T05:49:01Z | 2022-03-13T20:02:15Z | 34226 |
| 410 | *b18d778b4e4b6bf1fd5b2d790c941270145a6a6d* | .{0,1000}b18d778b4e4b6bf1fd5b2d790c941270145a6a6d.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #content | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 34496 |
| 411 | *b6ac954c208f9e813cbacebfbea30e9b71e252c9c35cea2aad4864cd9f1c492b* | .{0,1000}b6ac954c208f9e813cbacebfbea30e9b71e252c9c35cea2aad4864cd9f1c492b.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 34873 |
| 412 | *b89570294bb08b6ac4245fe0db6e35c1b23fa01ad3a9ac0bfe07043c7af3350c* | .{0,1000}b89570294bb08b6ac4245fe0db6e35c1b23fa01ad3a9ac0bfe07043c7af3350c.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 35020 | ||||
| 413 | *b898e52e3799d4c3c4fa328c400ba620c814c11ca23d0b7ec2f3fd7917a7e8a1* | .{0,1000}b898e52e3799d4c3c4fa328c400ba620c814c11ca23d0b7ec2f3fd7917a7e8a1.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 35021 | ||||
| 414 | *Backdoor:Script/HustleCon.A* | .{0,1000}Backdoor\:Script\/HustleCon\.A.{0,1000} | signature_keyword | rdp | rdp file received in emails - abused by attackers | T1204 - T1566 - T1078 - T1105 | TA0001 - TA0002 - TA0010 - TA0011 | N/A | Midnight Blizzard - APT29 - UNC2452 - Cozy Bear | Phishing | https://www.microsoft.com/en-us/security/blog/2024/10/29/midnight-blizzard-conducts-large-scale-spear-phishing-campaign-using-rdp-files | 1 | 0 | #Avsignature | N/A | 9 | 8 | N/A | N/A | N/A | N/A | 35197 |
| 415 | *bbtfr/evil-proxy* | .{0,1000}bbtfr\/evil\-proxy.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 1 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 35415 |
| 416 | *bd78ea00b16797551d4f40297f42e9b1f9d912f416a115c3eb10f340246a9d54* | .{0,1000}bd78ea00b16797551d4f40297f42e9b1f9d912f416a115c3eb10f340246a9d54.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 35546 | ||||
| 417 | *bdcfb9b63fd01bdd50427f205338e26e8001015b4fe14b6016cfb08e37c08a6e* | .{0,1000}bdcfb9b63fd01bdd50427f205338e26e8001015b4fe14b6016cfb08e37c08a6e.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 35565 | ||||
| 418 | *bdf7dee28fc21a09ae10d5e3a75e3a7713e705e78a40f55a4c003c9358174372* | .{0,1000}bdf7dee28fc21a09ae10d5e3a75e3a7713e705e78a40f55a4c003c9358174372.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 35576 | ||||
| 419 | *beb982a616c2c4cd716387b6a4c7a4b86ddcca0bc76faa94b4c5f10ed7abd592* | .{0,1000}beb982a616c2c4cd716387b6a4c7a4b86ddcca0bc76faa94b4c5f10ed7abd592.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 35743 | ||||
| 420 | *best*phish her* | .{0,1000}best.{0,1000}phish\sher.{0,1000} | offensive_tool_keyword | teamsphisher | Send phishing messages and attachments to Microsoft Teams users | T1566.001 - T1566.002 - T1204.001 | TA0001 - TA0005 | N/A | Black Basta | Phishing | https://github.com/Octoberfest7/TeamsPhisher | 1 | 0 | N/A | N/A | N/A | 10 | 1073 | 138 | 2024-06-19T21:41:55Z | 2023-07-03T02:19:47Z | 35823 |
| 421 | *bfa9dc4c4b911b6777cb98d17a82b28531c26600698699cbe658749684818f28* | .{0,1000}bfa9dc4c4b911b6777cb98d17a82b28531c26600698699cbe658749684818f28.{0,1000} | offensive_tool_keyword | PWA-Phishing | Phishing with Progressive Web Apps and UI manipulation | T1071.003 - T1204.002 - T1608.003 - T1071.004 | TA0006 | N/A | N/A | Phishing | https://github.com/mrd0x/PWA-Phishing | 1 | 0 | #filehash | N/A | 10 | 3 | 288 | 52 | 2024-06-16T17:47:15Z | 2024-06-09T19:47:52Z | 35879 |
| 422 | *build/evilginx* | .{0,1000}build\/evilginx.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | N/A | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 36355 |
| 423 | *c086c1e601dbde7b31cbaea56b915f22b1ebc21d744a431984406e6062b4b865* | .{0,1000}c086c1e601dbde7b31cbaea56b915f22b1ebc21d744a431984406e6062b4b865.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 36671 | ||||
| 424 | *c121f7d62fa5ecd27c3aaae5737a3de8f2e4def0c182058b6dd824aa92351e9c* | .{0,1000}c121f7d62fa5ecd27c3aaae5737a3de8f2e4def0c182058b6dd824aa92351e9c.{0,1000} | offensive_tool_keyword | gophish | Gophish is an open-source phishing toolkit designed for businesses and penetration testers. It provides the ability to quickly and easily setup and execute phishing engagements and security awareness training. | T1566 - T1598 | TA0008 - TA0009 | N/A | Black Basta | Phishing | https://github.com/gophish/gophish | 1 | 0 | #filehash | N/A | 10 | 10 | 12483 | 2528 | 2024-09-23T04:24:43Z | 2013-11-18T23:26:43Z | 36715 |
| 425 | *c2935d032a38a5a6d3251d22b9d93d08223b8dbf90efedbb0e6716cdafe76367* | .{0,1000}c2935d032a38a5a6d3251d22b9d93d08223b8dbf90efedbb0e6716cdafe76367.{0,1000} | offensive_tool_keyword | phishery | Phishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document. | T1566.001 - T1071 - T1204.002 | TA0001 | N/A | BERSERK BEAR | Phishing | https://github.com/ryhanson/phishery | 1 | 0 | #filehash | N/A | 9 | 10 | 993 | 209 | 2017-09-11T15:42:10Z | 2016-09-25T02:19:24Z | 36818 |
| 426 | *c6bd027f5269a980cd4deffcdbdab77eb317db2a9737d727b55fe37710cd2f95* | .{0,1000}c6bd027f5269a980cd4deffcdbdab77eb317db2a9737d727b55fe37710cd2f95.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 37164 | ||||
| 427 | *c7ffb81b3cd5cfcfe18363f998cd64428423814d5a8713d89e7992941884587d* | .{0,1000}c7ffb81b3cd5cfcfe18363f998cd64428423814d5a8713d89e7992941884587d.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 37258 | ||||
| 428 | *c923b2051d3e822e390e80c7e8d56f6b2cc62ae6688ca73745684b57154f3ecb* | .{0,1000}c923b2051d3e822e390e80c7e8d56f6b2cc62ae6688ca73745684b57154f3ecb.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 37339 | ||||
| 429 | *CamHacker has a new update!* | .{0,1000}CamHacker\shas\sa\snew\supdate!.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 37541 | ||||
| 430 | *CamHacker updated successfully* | .{0,1000}CamHacker\supdated\ssuccessfully.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 37542 | ||||
| 431 | *CamHacker/releases/latest/download/websites.zip* | .{0,1000}CamHacker\/releases\/latest\/download\/websites\.zip.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 1 | N/A | N/A | 10 | N/A | 37543 | ||||
| 432 | *cb0a620a960506193df32016f825248dec7fe504d8b857ee54a88ad1bdf8d9ce* | .{0,1000}cb0a620a960506193df32016f825248dec7fe504d8b857ee54a88ad1bdf8d9ce.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 37634 | ||||
| 433 | *cb4a4a24fdd61493e58d83befacd93981771c5e8e7ff206b1c6050134613ae4a* | .{0,1000}cb4a4a24fdd61493e58d83befacd93981771c5e8e7ff206b1c6050134613ae4a.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 37658 | ||||
| 434 | *cdb6b0d366c80ef521a59334a58f95ea5b7dbddc6e9f81ff28a11ec44ceba696* | .{0,1000}cdb6b0d366c80ef521a59334a58f95ea5b7dbddc6e9f81ff28a11ec44ceba696.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 37893 | ||||
| 435 | *cf2f9d4e499c45cf102ede7ccb8e0e4e44005f9cf0313024771dda337bd6e1dd* | .{0,1000}cf2f9d4e499c45cf102ede7ccb8e0e4e44005f9cf0313024771dda337bd6e1dd.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 38055 | ||||
| 436 | *clear; history -c* | .{0,1000}clear\;\shistory\s\-c.{0,1000} | offensive_tool_keyword | pastehakk | perform clipboard poisoning or paste jacking attack | T1115 | T0001 - T0002 - T0005 | N/A | N/A | Phishing | https://github.com/3xploitGuy/pastehakk | 1 | 0 | #linux | N/A | 7 | 1 | 56 | 10 | 2020-06-22T01:17:53Z | 2020-06-17T19:32:24Z | 38301 |
| 437 | *Cloudflared and Loclx have started successfully!* | .{0,1000}Cloudflared\sand\sLoclx\shave\sstarted\ssuccessfully!.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 38356 | ||||
| 438 | *Cloudflared has started successfully!* | .{0,1000}Cloudflared\shas\sstarted\ssuccessfully!.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 38357 | ||||
| 439 | *com.itgorillaz.lnk2pwn.model* | .{0,1000}com\.itgorillaz\.lnk2pwn\.model.{0,1000} | offensive_tool_keyword | lnk2pwn | Malicious Shortcut(.lnk) Generator | T1204 - T1059.007 | TA0001 - TA0002 | N/A | N/A | Phishing | https://github.com/it-gorillaz/lnk2pwn | 1 | 0 | N/A | N/A | 8 | 2 | 193 | 34 | 2018-11-23T17:18:49Z | 2018-11-23T00:12:48Z | 38636 |
| 440 | *const commandToRun = "mshta " + htaPath* | .{0,1000}const\scommandToRun\s\=\s\"mshta\s\"\s\+\shtaPath.{0,1000} | offensive_tool_keyword | recaptcha-phish | Phishing with a fake reCAPTCHA | T1566.001 - T1204.002 - T1071.003 | TA0001 - TA0002 | Lumma Stealer | N/A | Phishing | https://github.com/JohnHammond/recaptcha-phish | 1 | 0 | #content | N/A | 10 | 6 | 534 | 104 | 2024-09-13T11:18:29Z | 2024-09-13T07:00:40Z | 38787 |
| 441 | *core/http_proxy.go* | .{0,1000}core\/http_proxy\.go.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 1 | N/A | False positives expected | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 38895 |
| 442 | *CredPhisher.csproj* | .{0,1000}CredPhisher\.csproj.{0,1000} | offensive_tool_keyword | CredPhisher | Prompts the current user for their credentials using the CredUIPromptForWindowsCredentials WinAPI function | T1056.002 - T1111 | TA0004 | N/A | N/A | Phishing | https://github.com/matterpreter/OffensiveCSharp/tree/master/CredPhisher | 1 | 1 | N/A | N/A | 10 | 10 | 1416 | 250 | 2023-02-06T14:56:26Z | 2019-02-06T00:32:29Z | 39059 |
| 443 | *CredPhisher.exe* | .{0,1000}CredPhisher\.exe.{0,1000} | offensive_tool_keyword | CredPhisher | Prompts the current user for their credentials using the CredUIPromptForWindowsCredentials WinAPI function | T1056.002 - T1111 | TA0004 | N/A | N/A | Phishing | https://github.com/matterpreter/OffensiveCSharp/tree/master/CredPhisher | 1 | 1 | N/A | N/A | 10 | 10 | 1416 | 250 | 2023-02-06T14:56:26Z | 2019-02-06T00:32:29Z | 39060 |
| 444 | *cscript ..\\temp.vbs* | .{0,1000}cscript\s\.\.\\\\temp\.vbs.{0,1000} | offensive_tool_keyword | 365-Stealer | 365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack | T1111 - T1566.001 - T1078.004 | TA0004 - TA0001 - TA0040 | N/A | N/A | Phishing | https://github.com/AlteredSecurity/365-Stealer | 1 | 0 | N/A | N/A | 10 | 5 | 488 | 89 | 2024-06-08T21:03:50Z | 2020-09-20T18:22:36Z | 39156 |
| 445 | *D0:B6:9D:86:6D:AE:B4:E1:CA:F0:C1:F5:4D:82:45:7E:13:06:CD:1A:DE:49:A3:80:DC:21:6A:5C:A8:F4:84:1B* | .{0,1000}D0\:B6\:9D\:86\:6D\:AE\:B4\:E1\:CA\:F0\:C1\:F5\:4D\:82\:45\:7E\:13\:06\:CD\:1A\:DE\:49\:A3\:80\:DC\:21\:6A\:5C\:A8\:F4\:84\:1B.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/ms101/EvilKnievelnoVNC | 1 | 0 | #certificae #linux | N/A | 9 | 1 | 44 | 8 | 2025-03-08T19:34:41Z | 2024-04-13T22:05:04Z | 39329 |
| 446 | *D00Movenok/HTMLSmuggler* | .{0,1000}D00Movenok\/HTMLSmuggler.{0,1000} | offensive_tool_keyword | HTMLSmuggler | HTML Smuggling generator&obfuscator for your Red Team operations | T1564.001 - T1027 - T1566 | TA0005 | N/A | N/A | Phishing | https://github.com/D00Movenok/HTMLSmuggler | 1 | 1 | N/A | N/A | 10 | 2 | 162 | 19 | 2024-02-27T23:03:55Z | 2023-07-02T08:10:59Z | 39335 |
| 447 | *d0659e8489bc633b617e86f4e7994a593ada5cfc8463f79631d9672623b79750* | .{0,1000}d0659e8489bc633b617e86f4e7994a593ada5cfc8463f79631d9672623b79750.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 39356 | ||||
| 448 | *d10833b7d54745c35eec76ce48c1d8a4d90a9455bcd8b81cacdc95b9304b3be3* | .{0,1000}d10833b7d54745c35eec76ce48c1d8a4d90a9455bcd8b81cacdc95b9304b3be3.{0,1000} | offensive_tool_keyword | saycheese | Grab target's webcam shots by link | T1213 - T1071 - T1102 - T1123 - T1185 - T1200 | TA0001 - TA0005 - TA0009 - TA0011 | N/A | N/A | Phishing | https://github.com/hangetzzu/saycheese | 1 | 0 | #filehash | N/A | 9 | 10 | 1175 | 962 | 2024-06-18T23:39:41Z | 2019-04-29T04:07:00Z | 39410 |
| 449 | *d1fccb8acadbdefaf27f8680c74c40dba94e52734dd9704d38c0de7b10066f14* | .{0,1000}d1fccb8acadbdefaf27f8680c74c40dba94e52734dd9704d38c0de7b10066f14.{0,1000} | offensive_tool_keyword | lnk2pwn | Malicious Shortcut(.lnk) Generator | T1204 - T1059.007 | TA0001 - TA0002 | N/A | N/A | Phishing | https://github.com/it-gorillaz/lnk2pwn | 1 | 0 | #filehash | N/A | 8 | 2 | 193 | 34 | 2018-11-23T17:18:49Z | 2018-11-23T00:12:48Z | 39487 |
| 450 | *d546105ee91da0a53a26ed53f90414ea5f56a272caa137629125d018354f6b77* | .{0,1000}d546105ee91da0a53a26ed53f90414ea5f56a272caa137629125d018354f6b77.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 39721 | ||||
| 451 | *d5591f81fb5bd90d3af0954008ecfd433eeaf6ecc99941324747ca7433ae5985* | .{0,1000}d5591f81fb5bd90d3af0954008ecfd433eeaf6ecc99941324747ca7433ae5985.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 39728 | ||||
| 452 | *d561756dd8152cceb60d50ae5650eedcdb022f306f193017aede737428ff2452* | .{0,1000}d561756dd8152cceb60d50ae5650eedcdb022f306f193017aede737428ff2452.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 39730 | ||||
| 453 | *d9c7dc1a5a792486cc3853620eb700e26a047238ba92c757b4f9d40605dbd3b8* | .{0,1000}d9c7dc1a5a792486cc3853620eb700e26a047238ba92c757b4f9d40605dbd3b8.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 40033 | ||||
| 454 | *da2e2e4a0d34d63a452322f2fe5f57416aa79b6abb8a2a7cc3917a3b772d4cea* | .{0,1000}da2e2e4a0d34d63a452322f2fe5f57416aa79b6abb8a2a7cc3917a3b772d4cea.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 40054 | ||||
| 455 | *DancingRightToLeft.py* | .{0,1000}DancingRightToLeft\.py.{0,1000} | offensive_tool_keyword | phishing-HTML-linter | Phishing and Social-Engineering related scripts | T1566.001 - T1056.001 | TA0040 - TA0001 | N/A | N/A | Phishing | https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing | 1 | 1 | N/A | N/A | 10 | 10 | 2689 | 527 | 2023-06-27T19:16:49Z | 2018-02-02T21:24:03Z | 40123 |
| 456 | *dc25fef1e036e80dbbf1a5665fa13dc1ed6f8c56875161608cdf532d8a21a4a5* | .{0,1000}dc25fef1e036e80dbbf1a5665fa13dc1ed6f8c56875161608cdf532d8a21a4a5.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 40307 | ||||
| 457 | *ddb178cbaaab362c61d3d061b366625d205f208553ddf341b1c8fae466e5bd6f* | .{0,1000}ddb178cbaaab362c61d3d061b366625d205f208553ddf341b1c8fae466e5bd6f.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 40469 | ||||
| 458 | *Device architecture unknown. Download cloudflared/loclx manually* | .{0,1000}Device\sarchitecture\sunknown\.\sDownload\scloudflared\/loclx\smanually.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 40777 | ||||
| 459 | *'Disable all http access logs'* | .{0,1000}\'Disable\sall\shttp\saccess\slogs\'.{0,1000} | offensive_tool_keyword | 365-Stealer | 365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack | T1111 - T1566.001 - T1078.004 | TA0004 - TA0001 - TA0040 | N/A | N/A | Phishing | https://github.com/AlteredSecurity/365-Stealer | 1 | 0 | N/A | N/A | 10 | 5 | 488 | 89 | 2024-06-08T21:03:50Z | 2020-09-20T18:22:36Z | 40947 |
| 460 | *dnsmorph* | .{0,1000}dnsmorph.{0,1000} | offensive_tool_keyword | dnsmorph | DNSMORPH is a domain name permutation engine. inspired by dnstwist. It is written in Go making for a compact and very fast tool. It robustly handles any domain or subdomain supplied and provides a number of configuration options to tune permutation runs. | T1568.002 - T1568.003 - T1568.001 - T1568.004 | TA0009 - TA0011 | N/A | N/A | Phishing | https://github.com/netevert/dnsmorph | 1 | 1 | N/A | N/A | N/A | 3 | 266 | 43 | 2023-08-08T06:38:59Z | 2018-02-20T19:13:35Z | 41273 |
| 461 | *dnstwist* | .{0,1000}dnstwist.{0,1000} | offensive_tool_keyword | dnstwist | See what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence. | T1560 - T1565 - T1566 - T1568 - T1569 | TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/elceef/dnstwist | 1 | 0 | N/A | N/A | 3 | 10 | 5113 | 801 | 2025-04-15T18:41:47Z | 2015-06-11T12:24:17Z | 41291 |
| 462 | *docker rmi evilnginx* | .{0,1000}docker\srmi\sevilnginx.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 0 | N/A | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 41326 |
| 463 | *docker rmi evilnovnc* | .{0,1000}docker\srmi\sevilnovnc.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 0 | N/A | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 41327 |
| 464 | *domainhunter.py* | .{0,1000}domainhunter\.py.{0,1000} | offensive_tool_keyword | domainhunter | Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names | T1583.002 - T1568.002 | TA0011 - TA0009 | N/A | N/A | Phishing | https://github.com/threatexpress/domainhunter | 1 | 1 | N/A | N/A | N/A | 10 | 1587 | 292 | 2024-06-06T21:01:21Z | 2017-03-01T11:16:26Z | 41377 |
| 465 | *Don't_blindly_trust_obfuscated_code_it_might_do_something_bad* | .{0,1000}Don\'t_blindly_trust_obfuscated_code_it_might_do_something_bad.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 41418 | ||||
| 466 | *downloadMalwareDomains* | .{0,1000}downloadMalwareDomains.{0,1000} | offensive_tool_keyword | domainhunter | Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names | T1583.002 - T1568.002 | TA0011 - TA0009 | N/A | N/A | Phishing | https://github.com/threatexpress/domainhunter | 1 | 0 | N/A | N/A | N/A | 10 | 1587 | 292 | 2024-06-06T21:01:21Z | 2017-03-01T11:16:26Z | 41485 |
| 467 | *e094dc2a9ec5fe9800948a640f416fe610fdf155874e897d3cba6cc86f854083* | .{0,1000}e094dc2a9ec5fe9800948a640f416fe610fdf155874e897d3cba6cc86f854083.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 41766 | ||||
| 468 | *e0cc8936e11dcf4e016ff32f5a81aa15f352cb71ec8a24b383dc263e56425018* | .{0,1000}e0cc8936e11dcf4e016ff32f5a81aa15f352cb71ec8a24b383dc263e56425018.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 41779 | ||||
| 469 | *e22080246ffecef9d922c07fe2511b93f8b7d585b6a2c9b2d6332a93b2e5cf87* | .{0,1000}e22080246ffecef9d922c07fe2511b93f8b7d585b6a2c9b2d6332a93b2e5cf87.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 41883 |
| 470 | *e3130262a4adfed3a225075d6eb93c5caeeba93b1253dc1b148f8a80c5c35a03* | .{0,1000}e3130262a4adfed3a225075d6eb93c5caeeba93b1253dc1b148f8a80c5c35a03.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 41954 | ||||
| 471 | *e5474ff71a5e81a3fde493dde6141b25fbcff158367cc0fc492c063f0e59ca6a* | .{0,1000}e5474ff71a5e81a3fde493dde6141b25fbcff158367cc0fc492c063f0e59ca6a.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 42101 |
| 472 | *e5f220215fdf2ccc6b92dcbf95b6967d7a4f2bd4b0668413728c37bdd3833304* | .{0,1000}e5f220215fdf2ccc6b92dcbf95b6967d7a4f2bd4b0668413728c37bdd3833304.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 42144 |
| 473 | *e62d0d5e71daca0aa1c2e899b0da9668167fcbd20060ef8c01a8d8b66f0a32b3* | .{0,1000}e62d0d5e71daca0aa1c2e899b0da9668167fcbd20060ef8c01a8d8b66f0a32b3.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 42159 | ||||
| 474 | *e988e9a36810fb0fa0fb32556cb93c8ea4117e4176402ff74e397bd4a4d125d6* | .{0,1000}e988e9a36810fb0fa0fb32556cb93c8ea4117e4176402ff74e397bd4a4d125d6.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 42414 | ||||
| 475 | *ec57e5c4d592d1ad0a0e79b22e85f8173bcb3c03f4497957f90def4175ca383d* | .{0,1000}ec57e5c4d592d1ad0a0e79b22e85f8173bcb3c03f4497957f90def4175ca383d.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 42630 | ||||
| 476 | *echo 'user ALL=(ALL) NOPASSWD:ALL' >> /etc/sudoers* | .{0,1000}echo\s\'user\sALL\=\(ALL\)\sNOPASSWD\:ALL\'\s\>\>\s\/etc\/sudoers.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 0 | #linux | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 42739 |
| 477 | *ed4d66eac260c54457ea1b9fa50be035dc89b32e7a318bff1296606413f25cbb* | .{0,1000}ed4d66eac260c54457ea1b9fa50be035dc89b32e7a318bff1296606413f25cbb.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 42770 | ||||
| 478 | *ef0602ea7c5cfe523cd58fbfb20f835a908c5d3873fcb14510a042d13de53863* | .{0,1000}ef0602ea7c5cfe523cd58fbfb20f835a908c5d3873fcb14510a042d13de53863.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 42923 | ||||
| 479 | *embedInHTML.html* | .{0,1000}embedInHTML\.html.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 1 | N/A | N/A | N/A | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 43082 |
| 480 | *embedInHTML.py* | .{0,1000}embedInHTML\.py.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 1 | N/A | N/A | 10 | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 43083 |
| 481 | *EmbedInHTML-master* | .{0,1000}EmbedInHTML\-master.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 1 | N/A | N/A | 10 | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 43084 |
| 482 | *Enter your loclx authtoken:* | .{0,1000}Enter\syour\sloclx\sauthtoken\:.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 43178 | ||||
| 483 | *EvilClippy.exe* | .{0,1000}EvilClippy\.exe.{0,1000} | offensive_tool_keyword | EvilClippy | A cross-platform assistant for creating malicious MS Office documents | T1566.001 - T1059.001 - T1204.002 | TA0004 - TA0002 | N/A | N/A | Phishing | https://github.com/outflanknl/EvilClippy | 1 | 1 | N/A | N/A | 10 | 10 | 2165 | 402 | 2023-12-27T12:37:47Z | 2019-03-26T12:14:03Z | 43333 |
| 484 | *EvilClippy-master* | .{0,1000}EvilClippy\-master.{0,1000} | offensive_tool_keyword | EvilClippy | A cross-platform assistant for creating malicious MS Office documents | T1566.001 - T1059.001 - T1204.002 | TA0004 - TA0002 | N/A | N/A | Phishing | https://github.com/outflanknl/EvilClippy | 1 | 1 | N/A | N/A | 10 | 10 | 2165 | 402 | 2023-12-27T12:37:47Z | 2019-03-26T12:14:03Z | 43336 |
| 485 | *evilfeed.go* | .{0,1000}evilfeed\.go.{0,1000} | offensive_tool_keyword | gophish | Combination of evilginx2 and GoPhish | T1565-002 - T1565-003 - T1565-012 - T1110 - T1056-001 - T1113 | TA0002 - TA0003 | N/A | Black Basta | Phishing | https://github.com/fin3ss3g0d/evilgophish | 1 | 1 | N/A | N/A | 10 | 10 | 1762 | 340 | 2024-06-15T17:48:11Z | 2022-09-07T02:47:43Z | 43338 |
| 486 | *evilginx -p * | .{0,1000}evilginx\s\-p\s.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #linux | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 43339 |
| 487 | *evilginx -p* | .{0,1000}evilginx\s\-p.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | N/A | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 43340 |
| 488 | *evilginx* | .{0,1000}evilginx.{0,1000} | offensive_tool_keyword | evilginx2 | evilginx2 is a man-in-the-middle attack framework used for phishing login credentials along with session cookies. which in turn allows to bypass 2-factor authentication protection.This tool is a successor to Evilginx. released in 2017. which used a custom version of nginx HTTP server to provide man-in-the-middle functionality to act as a proxy between a browser and phished website. Present version is fully written in GO as a standalone application. which implements its own HTTP and DNS server. making it extremely easy to set up and use | T1556 - T1565 - T1056 - T1558 - T1110 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | N/A | N/A | 7 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 43341 |
| 489 | *evilginx.exe* | .{0,1000}evilginx\.exe.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 1 | N/A | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 43342 |
| 490 | *evilginx_linux* | .{0,1000}evilginx_linux.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 43343 |
| 491 | *evilginx_windows_* | .{0,1000}evilginx_windows_.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 43344 |
| 492 | *evilginx2* | .{0,1000}evilginx2.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 1 | N/A | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 43345 |
| 493 | *evilginx2/releases/* | .{0,1000}evilginx2\/releases\/.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 1 | N/A | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 43346 |
| 494 | *Evilginx2-Phishlets* | .{0,1000}Evilginx2\-Phishlets.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/Evilginx2-Phishlets | 1 | 0 | N/A | N/A | 10 | 7 | 670 | 263 | 2025-02-06T02:46:16Z | 2020-05-13T05:58:43Z | 43347 |
| 495 | *evilginx-linux* | .{0,1000}evilginx\-linux.{0,1000} | offensive_tool_keyword | gophish | Combination of evilginx2 and GoPhish | T1565-002 - T1565-003 - T1565-012 - T1110 - T1056-001 - T1113 | TA0002 - TA0003 | N/A | Black Basta | Phishing | https://github.com/fin3ss3g0d/evilgophish | 1 | 1 | #linux | N/A | 10 | 10 | 1762 | 340 | 2024-06-15T17:48:11Z | 2022-09-07T02:47:43Z | 43348 |
| 496 | *evilginx-mastery* | .{0,1000}evilginx\-mastery.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 1 | N/A | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 43349 |
| 497 | *evilginx-v3* | .{0,1000}evilginx\-v3.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 43350 |
| 498 | *evilgophish* | .{0,1000}evilgophish.{0,1000} | offensive_tool_keyword | gophish | Combination of evilginx2 and GoPhish | T1565-002 - T1565-003 - T1565-012 - T1110 - T1056-001 - T1113 | TA0002 - TA0003 | N/A | Black Basta | Phishing | https://github.com/fin3ss3g0d/evilgophish | 1 | 1 | N/A | N/A | 10 | 10 | 1762 | 340 | 2024-06-15T17:48:11Z | 2022-09-07T02:47:43Z | 43351 |
| 499 | *EvilnoVNC () * | .{0,1000}EvilnoVNC\s\(\)\s.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/ms101/EvilKnievelnoVNC | 1 | 0 | #linux #content | N/A | 9 | 1 | 44 | 8 | 2025-03-08T19:34:41Z | 2024-04-13T22:05:04Z | 43358 |
| 500 | *EvilnoVNC by @JoelGMSec* | .{0,1000}EvilnoVNC\sby\s\@JoelGMSec.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 0 | N/A | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 43359 |
| 501 | *EvilnoVNC Server* | .{0,1000}EvilnoVNC\sServer.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 0 | N/A | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 43360 |
| 502 | *evilnovnc.Dockerfile* | .{0,1000}evilnovnc\.Dockerfile.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 0 | N/A | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 43361 |
| 503 | *EvilnoVNC/run.sh* | .{0,1000}EvilnoVNC\/run\.sh.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/ms101/EvilKnievelnoVNC | 1 | 0 | #linux | N/A | 9 | 1 | 44 | 8 | 2025-03-08T19:34:41Z | 2024-04-13T22:05:04Z | 43362 |
| 504 | *EvilnoVNC/tmp/* | .{0,1000}EvilnoVNC\/tmp\/.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/ms101/EvilKnievelnoVNC | 1 | 0 | #linux | N/A | 9 | 1 | 44 | 8 | 2025-03-08T19:34:41Z | 2024-04-13T22:05:04Z | 43363 |
| 505 | *EvilnoVNC-main* | .{0,1000}EvilnoVNC\-main.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 1 | N/A | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 43364 |
| 506 | *eviloffice.exe * | .{0,1000}eviloffice\.exe\s.{0,1000} | offensive_tool_keyword | EvilClippy | A cross-platform assistant for creating malicious MS Office documents | T1566.001 - T1059.001 - T1204.002 | TA0004 - TA0002 | N/A | N/A | Phishing | https://github.com/outflanknl/EvilClippy | 1 | 0 | N/A | N/A | 10 | 10 | 2165 | 402 | 2023-12-27T12:37:47Z | 2019-03-26T12:14:03Z | 43365 |
| 507 | *eviloffice.exe* | .{0,1000}eviloffice\.exe.{0,1000} | offensive_tool_keyword | EvilClippy | A cross-platform assistant for creating malicious MS Office documents | T1566.001 - T1059.001 - T1204.002 | TA0004 - TA0002 | N/A | N/A | Phishing | https://github.com/outflanknl/EvilClippy | 1 | 1 | N/A | N/A | 10 | 10 | 2165 | 402 | 2023-12-27T12:37:47Z | 2019-03-26T12:14:03Z | 43366 |
| 508 | *evil-proxy.gemspec* | .{0,1000}evil\-proxy\.gemspec.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 1 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 43369 |
| 509 | *evil-proxy/agentproxy* | .{0,1000}evil\-proxy\/agentproxy.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 43370 |
| 510 | *evil-proxy/httpproxy* | .{0,1000}evil\-proxy\/httpproxy.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 43371 |
| 511 | *evil-proxy/selenium* | .{0,1000}evil\-proxy\/selenium.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 43372 |
| 512 | *evil-proxy/version* | .{0,1000}evil\-proxy\/version.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 43373 |
| 513 | *EvilProxy::HTTPProxyServer* | .{0,1000}EvilProxy\:\:HTTPProxyServer.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 43374 |
| 514 | *EvilProxy::MITMProxyServer* | .{0,1000}EvilProxy\:\:MITMProxyServer.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 43375 |
| 515 | *evil-proxy-0.1.0* | .{0,1000}evil\-proxy\-0\.1\.0.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 1 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 43376 |
| 516 | *evil-proxy-0.2.0* | .{0,1000}evil\-proxy\-0\.2\.0.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 1 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 43377 |
| 517 | *evil-proxy-master* | .{0,1000}evil\-proxy\-master.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 43378 |
| 518 | *evilqr-main* | .{0,1000}evilqr\-main.{0,1000} | offensive_tool_keyword | evilqr | Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice | T1566.002 - T1204.001 - T1192 | TA0001 - TA0005 | N/A | N/A | Phishing | https://github.com/kgretzky/evilqr | 1 | 1 | N/A | N/A | N/A | 3 | 292 | 45 | 2024-06-18T11:27:23Z | 2023-06-20T12:58:09Z | 43379 |
| 519 | *evilqr-phishing* | .{0,1000}evilqr\-phishing.{0,1000} | offensive_tool_keyword | evilqr | Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice | T1566.002 - T1204.001 - T1192 | TA0001 - TA0005 | N/A | N/A | Phishing | https://github.com/kgretzky/evilqr | 1 | 1 | N/A | N/A | N/A | 3 | 292 | 45 | 2024-06-18T11:27:23Z | 2023-06-20T12:58:09Z | 43380 |
| 520 | *evilqr-server* | .{0,1000}evilqr\-server.{0,1000} | offensive_tool_keyword | evilqr | Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice | T1566.002 - T1204.001 - T1192 | TA0001 - TA0005 | N/A | N/A | Phishing | https://github.com/kgretzky/evilqr | 1 | 1 | N/A | N/A | N/A | 3 | 292 | 45 | 2024-06-18T11:27:23Z | 2023-06-20T12:58:09Z | 43381 |
| 521 | *ExtensionSpoof.vbproj* | .{0,1000}ExtensionSpoof\.vbproj.{0,1000} | offensive_tool_keyword | ExtensionSpoofer | Spoof file icons and extensions in Windows | T1036 - T1027.005 - T1218 | TA0005 - TA0040 | N/A | N/A | Phishing | https://github.com/henriksb/ExtensionSpoofer | 1 | 0 | N/A | N/A | 9 | 2 | 179 | 65 | 2024-12-12T18:05:28Z | 2017-11-11T16:02:17Z | 43632 |
| 522 | *ExtensionSpoof.xml* | .{0,1000}ExtensionSpoof\.xml.{0,1000} | offensive_tool_keyword | ExtensionSpoofer | Spoof file icons and extensions in Windows | T1036 - T1027.005 - T1218 | TA0005 - TA0040 | N/A | N/A | Phishing | https://github.com/henriksb/ExtensionSpoofer | 1 | 0 | N/A | N/A | 9 | 2 | 179 | 65 | 2024-12-12T18:05:28Z | 2017-11-11T16:02:17Z | 43633 |
| 523 | *ExtensionSpoofer-1.zip* | .{0,1000}ExtensionSpoofer\-1\.zip.{0,1000} | offensive_tool_keyword | ExtensionSpoofer | Spoof file icons and extensions in Windows | T1036 - T1027.005 - T1218 | TA0005 - TA0040 | N/A | N/A | Phishing | https://github.com/henriksb/ExtensionSpoofer | 1 | 1 | N/A | N/A | 9 | 2 | 179 | 65 | 2024-12-12T18:05:28Z | 2017-11-11T16:02:17Z | 43634 |
| 524 | *-f payloads_examples/calc.* | .{0,1000}\-f\spayloads_examples\/calc\..{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 0 | N/A | N/A | N/A | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 43669 |
| 525 | *f5a5a21ee3a7dfaddae81cae7ef2df852cbfa44fdba51dfa0678a1c2d9d91c36* | .{0,1000}f5a5a21ee3a7dfaddae81cae7ef2df852cbfa44fdba51dfa0678a1c2d9d91c36.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 44048 | ||||
| 526 | *f90e3e0ba8b25e863b1d994d088376b2caedeed3b7bb5ee6c3f6e0e89bcaf023* | .{0,1000}f90e3e0ba8b25e863b1d994d088376b2caedeed3b7bb5ee6c3f6e0e89bcaf023.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 44277 | ||||
| 527 | *f9103918917348bf95b972701d8d4ccec36fdfd843792aa705b15454113cdfef* | .{0,1000}f9103918917348bf95b972701d8d4ccec36fdfd843792aa705b15454113cdfef.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 44279 |
| 528 | *FakeImageExploiter* | .{0,1000}FakeImageExploiter.{0,1000} | offensive_tool_keyword | FakeImageExploiter | This module takes one existing image.jpg and one payload.ps1 (input by user) and builds a new payload (agent.jpg.exe) that if executed it will trigger the download of the 2 previous files stored into apache2 (image.jpg + payload.ps1) and execute them. | T1564 - T1218 - T1204 - T1558.001 | TA0002 - TA0008 - TA0010 | N/A | N/A | Phishing | https://github.com/r00t-3xp10it/FakeImageExploiter | 1 | 1 | N/A | N/A | N/A | 10 | 912 | 338 | 2019-12-06T20:59:26Z | 2017-04-04T20:53:47Z | 44443 |
| 529 | *fb5ae202219536d7864043594d2c0b2909a956c5c88e33afc8efe588f5d84296* | .{0,1000}fb5ae202219536d7864043594d2c0b2909a956c5c88e33afc8efe588f5d84296.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #filehash | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 44490 |
| 530 | *FCD5E13D-1663-4226-8280-1C6A97933AB7* | .{0,1000}FCD5E13D\-1663\-4226\-8280\-1C6A97933AB7.{0,1000} | offensive_tool_keyword | ExtensionSpoofer | Spoof file icons and extensions in Windows | T1036 - T1027.005 - T1218 | TA0005 - TA0040 | N/A | N/A | Phishing | https://github.com/henriksb/ExtensionSpoofer | 1 | 0 | #GUIDproject | N/A | 9 | 2 | 179 | 65 | 2024-12-12T18:05:28Z | 2017-11-11T16:02:17Z | 44605 |
| 531 | *fd36746c68cdf7b32e63adaaa7b3e863b9769582f703722b88d9bf0b94030434* | .{0,1000}fd36746c68cdf7b32e63adaaa7b3e863b9769582f703722b88d9bf0b94030434.{0,1000} | offensive_tool_keyword | phishery | Phishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document. | T1566.001 - T1071 - T1204.002 | TA0001 | N/A | BERSERK BEAR | Phishing | https://github.com/ryhanson/phishery | 1 | 0 | #filehash | N/A | 9 | 10 | 993 | 209 | 2017-09-11T15:42:10Z | 2016-09-25T02:19:24Z | 44638 |
| 532 | *fdb2a63af6a5ae9aa60ceceb9e928188ac793a89f5282ed44c0d4be5f79559bb* | .{0,1000}fdb2a63af6a5ae9aa60ceceb9e928188ac793a89f5282ed44c0d4be5f79559bb.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 44678 | ||||
| 533 | *fdc984c09659c0ebf330d319bdebc772440dde7543aa6f74fd523a02fca2811d* | .{0,1000}fdc984c09659c0ebf330d319bdebc772440dde7543aa6f74fd523a02fca2811d.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 44685 | ||||
| 534 | *fe8db7541bc0c9d05dbd2e44e5eaa2bfd5c79968983860416636ea2792abfa5e* | .{0,1000}fe8db7541bc0c9d05dbd2e44e5eaa2bfd5c79968983860416636ea2792abfa5e.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 44748 | ||||
| 535 | *ff0f7b3bceac2a15be7b35bc7c1933b46ba6eeca6bba97dbd5227b59b913cb26* | .{0,1000}ff0f7b3bceac2a15be7b35bc7c1933b46ba6eeca6bba97dbd5227b59b913cb26.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 44798 | ||||
| 536 | *ffa5514b45c48061e412487d4defdeffa87a338213aa1bc4aabb3259ce18d7aa* | .{0,1000}ffa5514b45c48061e412487d4defdeffa87a338213aa1bc4aabb3259ce18d7aa.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 44832 | ||||
| 537 | *ffe1396fa56e5f86812443498cd6c8abfca613099df1261d08f06a73b14be042* | .{0,1000}ffe1396fa56e5f86812443498cd6c8abfca613099df1261d08f06a73b14be042.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #filehash | N/A | 10 | N/A | 44851 | ||||
| 538 | *FiercePhish* | .{0,1000}FiercePhish.{0,1000} | offensive_tool_keyword | FiercePhish | FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns. schedule sending of emails. and much more. The features will continue to be expanded and will include website spoofing. click tracking. and extensive notification options. | T1566 - T1566.001 - T1566.002 - T1566.003 | TA0001 - TA0002 - TA0003 - TA0006 | N/A | N/A | Phishing | https://github.com/Raikia/FiercePhish | 1 | 1 | N/A | N/A | N/A | 10 | 1351 | 255 | 2024-01-09T02:59:26Z | 2016-12-31T19:41:24Z | 44886 |
| 539 | *FluxionNetwork* | .{0,1000}FluxionNetwork.{0,1000} | offensive_tool_keyword | FluxionNetwork | Fluxion is a security auditing and social-engineering research tool. It is a remake of linset by vk496 with (hopefully) fewer bugs and more functionality. The script attempts to retrieve the WPA/WPA2 key from a target access point by means of a social engineering (phishing) attack. Its compatible with the latest release of Kali (rolling). Fluxions attacks' setup is mostly manual. but experimental auto-mode handles some of the attacks' setup parameters. Read the FAQ before requesting issues | T1559 - T1189 - T1059 - T1566 - T1056 | TA0001 - TA0002 - TA0009 | N/A | N/A | Phishing | https://github.com/FluxionNetwork/fluxion | 1 | 1 | N/A | N/A | N/A | 10 | 5207 | 1430 | 2023-11-03T23:16:30Z | 2017-04-29T10:22:27Z | 45183 |
| 540 | *fopen('credentials.txt'* | .{0,1000}fopen\(\'credentials\.txt\'.{0,1000} | offensive_tool_keyword | PWA-Phishing | Phishing with Progressive Web Apps and UI manipulation | T1071.003 - T1204.002 - T1608.003 - T1071.004 | TA0006 | N/A | N/A | Phishing | https://github.com/mrd0x/PWA-Phishing | 1 | 0 | N/A | N/A | 10 | 3 | 288 | 52 | 2024-06-16T17:47:15Z | 2024-06-09T19:47:52Z | 45195 |
| 541 | *gem 'evil-proxy'* | .{0,1000}gem\s\'evil\-proxy\'.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 45541 |
| 542 | *gophish*phish.go* | .{0,1000}gophish.{0,1000}phish\.go.{0,1000} | offensive_tool_keyword | gophish | Gophish is an open-source phishing toolkit designed for businesses and penetration testers. It provides the ability to quickly and easily setup and execute phishing engagements and security awareness training. | T1566 - T1598 | TA0008 - TA0009 | N/A | Black Basta | Phishing | https://github.com/gophish/gophish | 1 | 1 | N/A | N/A | 10 | 10 | 12483 | 2528 | 2024-09-23T04:24:43Z | 2013-11-18T23:26:43Z | 46605 |
| 543 | *gophish.go* | .{0,1000}gophish\.go.{0,1000} | offensive_tool_keyword | gophish | Open-Source Phishing Toolkit | T1566-001 - T1566-002 - T1566-003 - T1056-001 - T1113 - T1567-001 | TA0002 - TA0003 | N/A | Black Basta | Phishing | https://github.com/gophish/gophish | 1 | 1 | N/A | N/A | 10 | 10 | 12483 | 2528 | 2024-09-23T04:24:43Z | 2013-11-18T23:26:43Z | 46606 |
| 544 | *gophish/gophish* | .{0,1000}gophish\/gophish.{0,1000} | offensive_tool_keyword | gophish | Gophish is an open-source phishing toolkit designed for businesses and penetration testers. It provides the ability to quickly and easily setup and execute phishing engagements and security awareness training. | T1566 - T1598 | TA0008 - TA0009 | N/A | Black Basta | Phishing | https://github.com/gophish/gophish | 1 | 1 | N/A | N/A | 10 | 10 | 12483 | 2528 | 2024-09-23T04:24:43Z | 2013-11-18T23:26:43Z | 46607 |
| 545 | *gophish-send-mail.py* | .{0,1000}gophish\-send\-mail\.py.{0,1000} | offensive_tool_keyword | phishing-HTML-linter | Phishing and Social-Engineering related scripts | T1566.001 - T1056.001 | TA0040 - TA0001 | N/A | N/A | Phishing | https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing | 1 | 1 | N/A | N/A | 10 | 10 | 2689 | 527 | 2023-06-27T19:16:49Z | 2018-02-02T21:24:03Z | 46608 |
| 546 | *handlePhishlets* | .{0,1000}handlePhishlets.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #linux #content | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 46996 |
| 547 | *henriksb/ExtensionSpoofer* | .{0,1000}henriksb\/ExtensionSpoofer.{0,1000} | offensive_tool_keyword | ExtensionSpoofer | Spoof file icons and extensions in Windows | T1036 - T1027.005 - T1218 | TA0005 - TA0040 | N/A | N/A | Phishing | https://github.com/henriksb/ExtensionSpoofer | 1 | 0 | N/A | N/A | 9 | 2 | 179 | 65 | 2024-12-12T18:05:28Z | 2017-11-11T16:02:17Z | 47117 |
| 548 | *Hey Dear! You Have Won Free Rs 399 Jio Recharge* | .{0,1000}Hey\sDear!\sYou\sHave\sWon\sFree\sRs\s399\sJio\sRecharge.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 47142 | ||||
| 549 | *'Host the Phising App'* | .{0,1000}\'Host\sthe\sPhising\sApp\'.{0,1000} | offensive_tool_keyword | 365-Stealer | 365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack | T1111 - T1566.001 - T1078.004 | TA0004 - TA0001 - TA0040 | N/A | N/A | Phishing | https://github.com/AlteredSecurity/365-Stealer | 1 | 0 | N/A | N/A | 10 | 5 | 488 | 89 | 2024-06-08T21:03:50Z | 2020-09-20T18:22:36Z | 47282 |
| 550 | *HTMLSmuggler-main* | .{0,1000}HTMLSmuggler\-main.{0,1000} | offensive_tool_keyword | HTMLSmuggler | HTML Smuggling generator&obfuscator for your Red Team operations | T1564.001 - T1027 - T1566 | TA0005 | N/A | N/A | Phishing | https://github.com/D00Movenok/HTMLSmuggler | 1 | 1 | N/A | N/A | 10 | 2 | 162 | 19 | 2024-02-27T23:03:55Z | 2023-07-02T08:10:59Z | 47317 |
| 551 | *http://*.trycloudfare.com* | .{0,1000}http\:\/\/.{0,1000}\.trycloudfare\.com.{0,1000} | greyware_tool_keyword | trycloudflare.com | The subdomain .trycloudflare.com is a temporary hostname provided by Cloudflare Tunnel - It allows users to expose local services to the internet without needing to configure port forwarding or a public IP - attackers frequently abuse it for malicious activities | T1071.001 - T1090 - T1583.003 - T1102 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | Phishing | https://www.forcepoint.com/blog/x-labs/asyncrat-python-trycloudflare-malware | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47390 |
| 552 | *http://101.251.217.210* | .{0,1000}http\:\/\/101\.251\.217\.210.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 1 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 47403 |
| 553 | *http://127.0.0.1:35000* | .{0,1000}http\:\/\/127\.0\.0\.1\:35000.{0,1000} | offensive_tool_keyword | evilqr | Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice | T1566.002 - T1204.001 - T1192 | TA0001 - TA0005 | N/A | N/A | Phishing | https://github.com/kgretzky/evilqr | 1 | 1 | N/A | N/A | N/A | 3 | 292 | 45 | 2024-06-18T11:27:23Z | 2023-06-20T12:58:09Z | 47418 |
| 554 | *HTTPClient.post('https://httpbin.org/post* | .{0,1000}HTTPClient\.post\(\'https\:\/\/httpbin\.org\/post.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 47570 |
| 555 | *https://*.trycloudfare.com* | .{0,1000}https\:\/\/.{0,1000}\.trycloudfare\.com.{0,1000} | greyware_tool_keyword | trycloudflare.com | The subdomain .trycloudflare.com is a temporary hostname provided by Cloudflare Tunnel - It allows users to expose local services to the internet without needing to configure port forwarding or a public IP - attackers frequently abuse it for malicious activities | T1071.001 - T1090 - T1583.003 - T1102 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | Phishing | https://www.forcepoint.com/blog/x-labs/asyncrat-python-trycloudflare-malware | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47616 |
| 556 | *https://api.localxpose.io/api/v2/downloads/loclx-darwin-amd64.zip* | .{0,1000}https\:\/\/api\.localxpose\.io\/api\/v2\/downloads\/loclx\-darwin\-amd64\.zip.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 1 | #linux | N/A | 10 | N/A | 47663 | ||||
| 557 | *https://best-wishes-to-you* | .{0,1000}https\:\/\/best\-wishes\-to\-you.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 47685 | ||||
| 558 | *https://free-399rs-jio-recharge* | .{0,1000}https\:\/\/free\-399rs\-jio\-recharge.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 47767 | ||||
| 559 | *https://googleweblight.com/i?u=*ipfs.*.html* | .{0,1000}https\:\/\/googleweblight\.com\/i\?u\=.{0,1000}ipfs\..{0,1000}\.html.{0,1000} | greyware_tool_keyword | googleweblight.com | Open Redirect vulnerability being exploited by threat actors in Google Web Light | T1584.001 - T1534 | TA0008 | N/A | N/A | Phishing | https://x.com/1ZRR4H/status/1723062039680000255 | 1 | 1 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 47786 |
| 560 | *https://join-zoom-online-meeting* | .{0,1000}https\:\/\/join\-zoom\-online\-meeting.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 47802 | ||||
| 561 | *https://mrd0x.com/progressive-web-apps-pwa-phishing* | .{0,1000}https\:\/\/mrd0x\.com\/progressive\-web\-apps\-pwa\-phishing.{0,1000} | offensive_tool_keyword | PWA-Phishing | Phishing with Progressive Web Apps and UI manipulation | T1071.003 - T1204.002 - T1608.003 - T1071.004 | TA0006 | N/A | N/A | Phishing | https://github.com/mrd0x/PWA-Phishing | 1 | 1 | N/A | N/A | 10 | 3 | 288 | 52 | 2024-06-16T17:47:15Z | 2024-06-09T19:47:52Z | 47843 |
| 562 | *https://raw.githubusercontent.com/KasRoudra/CamHacker* | .{0,1000}https\:\/\/raw\.githubusercontent\.com\/KasRoudra\/CamHacker.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 1 | N/A | N/A | 10 | N/A | 47903 | ||||
| 563 | *https://saycheese*.serveo.net* | .{0,1000}https\:\/\/saycheese.{0,1000}\.serveo\.net.{0,1000} | offensive_tool_keyword | saycheese | Grab target's webcam shots by link | T1213 - T1071 - T1102 - T1123 - T1185 - T1200 | TA0001 - TA0005 - TA0009 - TA0011 | N/A | N/A | Phishing | https://github.com/hangetzzu/saycheese | 1 | 1 | N/A | N/A | 9 | 10 | 1175 | 962 | 2024-06-18T23:39:41Z | 2019-04-29T04:07:00Z | 47918 |
| 564 | *https://watch-youtube-videos-live* | .{0,1000}https\:\/\/watch\-youtube\-videos\-live.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 47986 | ||||
| 565 | *https://we.tl/t-* | .{0,1000}https\:\/\/we\.tl\/t\-.{0,1000} | greyware_tool_keyword | wetransfer | WeTransfer is a popular file sharing service often used by malicious actors for phishing campaigns due to its legitimate reputation and widespread use even within some enterprises to share files | T1608.001 - T1566 - T1002 - T1048 - T1204 | TA0001 - TA0002 - TA0010 | N/A | EXOTIC LILY | Phishing | https://twitter.com/mthcht/status/1658853848323182597 | 1 | 1 | N/A | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 47987 |
| 566 | *https://wetransfer.com/api/v4/transfers/* | .{0,1000}https\:\/\/wetransfer\.com\/api\/v4\/transfers\/.{0,1000} | greyware_tool_keyword | wetransfer | WeTransfer is a popular file-sharing service often used by malicious actors for phishing campaigns due to its legitimate reputation and widespread use even within some enterprises to share files | T1608.001 - T1566 - T1002 - T1048 - T1204 | TA0001 - TA0002 - TA0010 | N/A | EXOTIC LILY | Phishing | https://twitter.com/mthcht/status/1658853848323182597 | 1 | 1 | #filehostingservice | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 47991 |
| 567 | *https://wetransfer.com/downloads/* | .{0,1000}https\:\/\/wetransfer\.com\/downloads\/.{0,1000} | greyware_tool_keyword | wetransfer | WeTransfer is a popular file-sharing service often used by malicious actors for phishing campaigns due to its legitimate reputation and widespread use even within some enterprises to share files | T1608.001 - T1566 - T1002 - T1048 - T1204 | TA0001 - TA0002 - TA0010 | N/A | EXOTIC LILY | Phishing | https://twitter.com/mthcht/status/1658853848323182597 | 1 | 1 | N/A | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 47992 |
| 568 | *I am not a robot - reCAPTCHA Verification ID: 2165* | .{0,1000}I\sam\snot\sa\srobot\s\-\sreCAPTCHA\sVerification\sID\:\s2165.{0,1000} | offensive_tool_keyword | recaptcha-phish | Phishing with a fake reCAPTCHA | T1566.001 - T1204.002 - T1071.003 | TA0001 - TA0002 | Lumma Stealer | N/A | Phishing | https://github.com/JohnHammond/recaptcha-phish | 1 | 0 | N/A | N/A | 10 | 6 | 534 | 104 | 2024-09-13T11:18:29Z | 2024-09-13T07:00:40Z | 48093 |
| 569 | *I am not a robot - reCAPTCHA Verification ID: 3029* | .{0,1000}I\sam\snot\sa\srobot\s\-\sreCAPTCHA\sVerification\sID\:\s3029.{0,1000} | offensive_tool_keyword | recaptcha-phish | Phishing with a fake reCAPTCHA | T1566.001 - T1204.002 - T1071.003 | TA0001 - TA0002 | Lumma Stealer | N/A | Phishing | https://github.com/JohnHammond/recaptcha-phish | 1 | 0 | N/A | N/A | 10 | 6 | 534 | 104 | 2024-09-13T11:18:29Z | 2024-09-13T07:00:40Z | 48094 |
| 570 | *I am not a robot - reCAPTCHA Verification ID: 4202* | .{0,1000}I\sam\snot\sa\srobot\s\-\sreCAPTCHA\sVerification\sID\:\s4202.{0,1000} | offensive_tool_keyword | recaptcha-phish | Phishing with a fake reCAPTCHA | T1566.001 - T1204.002 - T1071.003 | TA0001 - TA0002 | Lumma Stealer | N/A | Phishing | https://github.com/JohnHammond/recaptcha-phish | 1 | 0 | N/A | N/A | 10 | 6 | 534 | 104 | 2024-09-13T11:18:29Z | 2024-09-13T07:00:40Z | 48095 |
| 571 | *I am not a robot - reCAPTCHA Verification ID: 7537* | .{0,1000}I\sam\snot\sa\srobot\s\-\sreCAPTCHA\sVerification\sID\:\s7537.{0,1000} | offensive_tool_keyword | recaptcha-phish | Phishing with a fake reCAPTCHA | T1566.001 - T1204.002 - T1071.003 | TA0001 - TA0002 | Lumma Stealer | N/A | Phishing | https://github.com/JohnHammond/recaptcha-phish | 1 | 0 | N/A | N/A | 10 | 6 | 534 | 104 | 2024-09-13T11:18:29Z | 2024-09-13T07:00:40Z | 48096 |
| 572 | *I am not a robot - reCAPTCHA Verification ID: 7624* | .{0,1000}I\sam\snot\sa\srobot\s\-\sreCAPTCHA\sVerification\sID\:\s7624.{0,1000} | offensive_tool_keyword | recaptcha-phish | Phishing with a fake reCAPTCHA | T1566.001 - T1204.002 - T1071.003 | TA0001 - TA0002 | Lumma Stealer | N/A | Phishing | https://github.com/JohnHammond/recaptcha-phish | 1 | 0 | N/A | N/A | 10 | 6 | 534 | 104 | 2024-09-13T11:18:29Z | 2024-09-13T07:00:40Z | 48097 |
| 573 | *I am not a robot - reCAPTCHA Verification ID: 93752* | .{0,1000}I\sam\snot\sa\srobot\s\-\sreCAPTCHA\sVerification\sID\:\s93752.{0,1000} | offensive_tool_keyword | recaptcha-phish | Phishing with a fake reCAPTCHA | T1566.001 - T1204.002 - T1071.003 | TA0001 - TA0002 | Lumma Stealer | N/A | Phishing | https://github.com/JohnHammond/recaptcha-phish | 1 | 0 | N/A | N/A | 10 | 6 | 534 | 104 | 2024-09-13T11:18:29Z | 2024-09-13T07:00:40Z | 48098 |
| 574 | *Import stealed session to Chromium..* | .{0,1000}Import\sstealed\ssession\sto\sChromium\.\..{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 0 | #content | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 48401 |
| 575 | *InjectApp.InfectClickonceApp(* | .{0,1000}InjectApp\.InfectClickonceApp\(.{0,1000} | offensive_tool_keyword | clickjack | automate abuse of clickonce applications | T1210 - T1204 - T1071.001 | TA0001 - TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/trustedsec/The_Shelf | 1 | 0 | N/A | N/A | 10 | 3 | 247 | 14 | 2024-11-25T19:33:34Z | 2024-05-22T14:31:52Z | 48513 |
| 576 | *Injected Word document has been saved!* | .{0,1000}Injected\sWord\sdocument\shas\sbeen\ssaved!.{0,1000} | offensive_tool_keyword | phishery | Phishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document. | T1566.001 - T1071 - T1204.002 | TA0001 | N/A | BERSERK BEAR | Phishing | https://github.com/ryhanson/phishery | 1 | 0 | #content | N/A | 9 | 10 | 993 | 209 | 2017-09-11T15:42:10Z | 2016-09-25T02:19:24Z | 48524 |
| 577 | *it-gorillaz/lnk2pwn* | .{0,1000}it\-gorillaz\/lnk2pwn.{0,1000} | offensive_tool_keyword | lnk2pwn | Malicious Shortcut(.lnk) Generator | T1204 - T1059.007 | TA0001 - TA0002 | N/A | N/A | Phishing | https://github.com/it-gorillaz/lnk2pwn | 1 | 1 | N/A | N/A | 8 | 2 | 193 | 34 | 2018-11-23T17:18:49Z | 2018-11-23T00:12:48Z | 49955 |
| 578 | *JoelGMSec - https://darkbyte.net* | .{0,1000}JoelGMSec\s\-\shttps\:\/\/darkbyte\.net.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 0 | #linux | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 50074 |
| 579 | *JoelGMSec/EvilnoVNC* | .{0,1000}JoelGMSec\/EvilnoVNC.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1566.001 - T1071 - T1071.001 | TA0043 - TA0001 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 1 | N/A | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 50075 |
| 580 | *JohnHammond/recaptcha-phish* | .{0,1000}JohnHammond\/recaptcha\-phish.{0,1000} | offensive_tool_keyword | recaptcha-phish | Phishing with a fake reCAPTCHA | T1566.001 - T1204.002 - T1071.003 | TA0001 - TA0002 | Lumma Stealer | N/A | Phishing | https://github.com/JohnHammond/recaptcha-phish | 1 | 1 | N/A | N/A | 10 | 6 | 534 | 104 | 2024-09-13T11:18:29Z | 2024-09-13T07:00:40Z | 50116 |
| 581 | *KasRoudra/CamHacker* | .{0,1000}KasRoudra\/CamHacker.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 1 | N/A | N/A | 10 | N/A | 50228 | ||||
| 582 | *kasroudrard@gmail.com* | .{0,1000}kasroudrard\@gmail\.com.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | 10 | N/A | 50229 | |||||
| 583 | *keylogger.py* | .{0,1000}keylogger\.py.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 0 | N/A | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 50424 |
| 584 | *kgretzky/evilginx2* | .{0,1000}kgretzky\/evilginx2.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 1 | N/A | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 50439 |
| 585 | *kgretzky/evilqr* | .{0,1000}kgretzky\/evilqr.{0,1000} | offensive_tool_keyword | evilqr | Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice | T1566.002 - T1204.001 - T1192 | TA0001 - TA0005 | N/A | N/A | Phishing | https://github.com/kgretzky/evilqr | 1 | 1 | N/A | N/A | N/A | 3 | 292 | 45 | 2024-06-18T11:27:23Z | 2023-06-20T12:58:09Z | 50440 |
| 586 | *kiosk.sh*startVNC.sh* | .{0,1000}kiosk\.sh.{0,1000}startVNC\.sh.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 0 | #linux | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 50484 |
| 587 | *localhost:1337* | .{0,1000}localhost\:1337.{0,1000} | offensive_tool_keyword | gophish | Combination of evilginx2 and GoPhish | T1565-002 - T1565-003 - T1565-012 - T1110 - T1056-001 - T1113 | TA0002 - TA0003 | N/A | Black Basta | Phishing | https://github.com/fin3ss3g0d/evilgophish | 1 | 1 | N/A | N/A | 10 | 10 | 1762 | 340 | 2024-06-15T17:48:11Z | 2022-09-07T02:47:43Z | 51213 |
| 588 | *location:\\*.trycloudfare.com* | .{0,1000}location\:\\\\.{0,1000}\.trycloudfare\.com.{0,1000} | greyware_tool_keyword | trycloudflare.com | The subdomain .trycloudflare.com is a temporary hostname provided by Cloudflare Tunnel - It allows users to expose local services to the internet without needing to configure port forwarding or a public IP - attackers frequently abuse it for malicious activities | T1071.001 - T1090 - T1583.003 - T1102 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | Phishing | https://www.forcepoint.com/blog/x-labs/asyncrat-python-trycloudflare-malware | 1 | 0 | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 51253 | |
| 589 | *lures create * | .{0,1000}lures\screate\s.{0,1000} | offensive_tool_keyword | gophish | Combination of evilginx2 and GoPhish | T1565-002 - T1565-003 - T1565-012 - T1110 - T1056-001 - T1113 | TA0002 - TA0003 | N/A | Black Basta | Phishing | https://github.com/fin3ss3g0d/evilgophish | 1 | 0 | N/A | N/A | 10 | 10 | 1762 | 340 | 2024-06-15T17:48:11Z | 2022-09-07T02:47:43Z | 51478 |
| 590 | *MacroDetectSandbox.vbs* | .{0,1000}MacroDetectSandbox\.vbs.{0,1000} | offensive_tool_keyword | phishing-HTML-linter | Phishing and Social-Engineering related scripts | T1566.001 - T1056.001 | TA0040 - TA0001 | N/A | N/A | Phishing | https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing | 1 | 1 | N/A | N/A | 10 | 10 | 2689 | 527 | 2023-06-27T19:16:49Z | 2018-02-02T21:24:03Z | 51532 |
| 591 | *Malicious Shortcut(.lnk) Generator* | .{0,1000}Malicious\sShortcut\(\.lnk\)\sGenerator.{0,1000} | offensive_tool_keyword | lnk2pwn | Malicious Shortcut(.lnk) Generator | T1204 - T1059.007 | TA0001 - TA0002 | N/A | N/A | Phishing | https://github.com/it-gorillaz/lnk2pwn | 1 | 0 | N/A | N/A | 8 | 2 | 193 | 34 | 2018-11-23T17:18:49Z | 2018-11-23T00:12:48Z | 51599 |
| 592 | *MIIEowIBAAKCAQEAvZtOCbMyFKJN3n89nctTfYLSeiCTNG01rAFl06hMkobyzr0c* | .{0,1000}MIIEowIBAAKCAQEAvZtOCbMyFKJN3n89nctTfYLSeiCTNG01rAFl06hMkobyzr0c.{0,1000} | offensive_tool_keyword | 365-Stealer | 365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack | T1111 - T1566.001 - T1078.004 | TA0004 - TA0001 - TA0040 | N/A | N/A | Phishing | https://github.com/AlteredSecurity/365-Stealer | 1 | 0 | N/A | N/A | 10 | 5 | 488 | 89 | 2024-06-08T21:03:50Z | 2020-09-20T18:22:36Z | 51990 |
| 593 | *mitmproxy.rb* | .{0,1000}mitmproxy\.rb.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 52160 |
| 594 | *module EvilProxy* | .{0,1000}module\sEvilProxy.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 52234 |
| 595 | *Mozilla/5.0 (*-bit) dnstwist* | .{0,1000}Mozilla\/5\.0\s\(.{0,1000}\-bit\)\sdnstwist.{0,1000} | offensive_tool_keyword | dnstwist | See what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence. | T1560 - T1565 - T1566 - T1568 - T1569 | TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/elceef/dnstwist | 1 | 1 | #useragent | N/A | 3 | 10 | 5113 | 801 | 2025-04-15T18:41:47Z | 2015-06-11T12:24:17Z | 52297 |
| 596 | *mrd0x/PWA-Phishing* | .{0,1000}mrd0x\/PWA\-Phishing.{0,1000} | offensive_tool_keyword | PWA-Phishing | Phishing with Progressive Web Apps and UI manipulation | T1071.003 - T1204.002 - T1608.003 - T1071.004 | TA0006 | N/A | N/A | Phishing | https://github.com/mrd0x/PWA-Phishing | 1 | 1 | N/A | N/A | 10 | 3 | 288 | 52 | 2024-06-16T17:47:15Z | 2024-06-09T19:47:52Z | 52318 |
| 597 | *mshta*I am not a robot - *Verification ID: * | .{0,1000}mshta.{0,1000}I\sam\snot\sa\srobot\s\-\s.{0,1000}Verification\sID\:\s.{0,1000} | offensive_tool_keyword | recaptcha-phish | Phishing with a fake reCAPTCHA | T1566.001 - T1204.002 - T1071.003 | TA0001 - TA0002 | Lumma Stealer | N/A | Phishing | https://github.com/JohnHammond/recaptcha-phish | 1 | 0 | N/A | https://x.com/skocherhan/status/1888762808948367410/photo/2 | 10 | 6 | 534 | 104 | 2024-09-13T11:18:29Z | 2024-09-13T07:00:40Z | 52406 |
| 598 | *mshta.exe*I am not a robot - reCAPTCHA Verification ID: * | .{0,1000}mshta\.exe.{0,1000}I\sam\snot\sa\srobot\s\-\sreCAPTCHA\sVerification\sID\:\s.{0,1000} | greyware_tool_keyword | mshta | Phishing with a fake reCAPTCHA | T1566.001 - T1204.002 - T1071.003 | TA0001 - TA0002 | Lumma Stealer | N/A | Phishing | https://github.com/JohnHammond/recaptcha-phish | 1 | 0 | N/A | N/A | 10 | 6 | 534 | 104 | 2024-09-13T11:18:29Z | 2024-09-13T07:00:40Z | 52415 |
| 599 | *mshta.exe*I am not a robot - reCAPTCHA Verification ID: * | .{0,1000}mshta\.exe.{0,1000}I\sam\snot\sa\srobot\s\-\sreCAPTCHA\sVerification\sID\:\s.{0,1000} | offensive_tool_keyword | recaptcha-phish | Phishing with a fake reCAPTCHA | T1566.001 - T1204.002 - T1071.003 | TA0001 - TA0002 | Lumma Stealer | N/A | Phishing | https://github.com/JohnHammond/recaptcha-phish | 1 | 0 | N/A | N/A | 10 | 6 | 534 | 104 | 2024-09-13T11:18:29Z | 2024-09-13T07:00:40Z | 52416 |
| 600 | *myreallycooltotallyrealtenant.onmicrosoft.com* | .{0,1000}myreallycooltotallyrealtenant\.onmicrosoft\.com.{0,1000} | offensive_tool_keyword | teamsphisher | Send phishing messages and attachments to Microsoft Teams users | T1566.001 - T1566.002 - T1204.001 | TA0001 - TA0005 | N/A | Black Basta | Phishing | https://github.com/Octoberfest7/TeamsPhisher | 1 | 1 | N/A | N/A | N/A | 10 | 1073 | 138 | 2024-06-19T21:41:55Z | 2023-07-03T02:19:47Z | 52530 |
| 601 | *namespace CredPhisher* | .{0,1000}namespace\sCredPhisher.{0,1000} | offensive_tool_keyword | CredPhisher | Prompts the current user for their credentials using the CredUIPromptForWindowsCredentials WinAPI function | T1056.002 - T1111 | TA0004 | N/A | N/A | Phishing | https://github.com/matterpreter/OffensiveCSharp/tree/master/CredPhisher | 1 | 0 | N/A | N/A | 10 | 10 | 1416 | 250 | 2023-02-06T14:56:26Z | 2019-02-06T00:32:29Z | 52603 |
| 602 | *nandydark/Linux-keylogger* | .{0,1000}nandydark\/Linux\-keylogger.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 0 | #linux | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 52627 |
| 603 | *novnc_proxy --vnc localhost:* | .{0,1000}novnc_proxy\s\-\-vnc\slocalhost\:.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 0 | #linux | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 53587 |
| 604 | *o365-Attack-Toolkit* | .{0,1000}o365\-Attack\-Toolkit.{0,1000} | offensive_tool_keyword | 365-Stealer | 365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack | T1111 - T1566.001 - T1078.004 | TA0004 - TA0001 - TA0040 | N/A | N/A | Phishing | https://github.com/AlteredSecurity/365-Stealer | 1 | 0 | N/A | N/A | 10 | 5 | 488 | 89 | 2024-06-08T21:03:50Z | 2020-09-20T18:22:36Z | 53791 |
| 605 | *objShell.Run "calc.exe"* | .{0,1000}objShell\.Run\s\"calc\.exe\".{0,1000} | offensive_tool_keyword | recaptcha-phish | Phishing with a fake reCAPTCHA | T1566.001 - T1204.002 - T1071.003 | TA0001 - TA0002 | Lumma Stealer | N/A | Phishing | https://github.com/JohnHammond/recaptcha-phish | 1 | 0 | #content | N/A | 10 | 6 | 534 | 104 | 2024-09-13T11:18:29Z | 2024-09-13T07:00:40Z | 53826 |
| 606 | *Octoberfest7/TeamsPhisher* | .{0,1000}Octoberfest7\/TeamsPhisher.{0,1000} | offensive_tool_keyword | teamsphisher | Send phishing messages and attachments to Microsoft Teams users | T1566.001 - T1566.002 - T1204.001 | TA0001 - TA0005 | N/A | Black Basta | Phishing | https://github.com/Octoberfest7/TeamsPhisher | 1 | 1 | N/A | N/A | N/A | 10 | 1073 | 138 | 2024-06-19T21:41:55Z | 2023-07-03T02:19:47Z | 53833 |
| 607 | *Office-DDE-Payloads* | .{0,1000}Office\-DDE\-Payloads.{0,1000} | offensive_tool_keyword | Office-DDE-Payloads | Collection of scripts and templates to generate Word and Excel documents embedded with the DDE. macro-less command execution technique described by @_staaldraad and @0x5A1F (blog post link in References section below). Intended for use during sanctioned red team engagements and/or phishing campaigns. | T1221 - T1222 - T1223 | TA0001 - TA0002 - TA0003 | N/A | N/A | Phishing | https://github.com/0xdeadbeefJERKY/Office-DDE-Payloads | 1 | 1 | N/A | N/A | N/A | 7 | 638 | 155 | 2023-07-16T08:22:24Z | 2017-10-27T22:19:17Z | 53849 |
| 608 | *outflanknl/EvilClippy* | .{0,1000}outflanknl\/EvilClippy.{0,1000} | offensive_tool_keyword | EvilClippy | A cross-platform assistant for creating malicious MS Office documents | T1566.001 - T1059.001 - T1204.002 | TA0004 - TA0002 | N/A | N/A | Phishing | https://github.com/outflanknl/EvilClippy | 1 | 1 | N/A | N/A | 10 | 10 | 2165 | 402 | 2023-12-27T12:37:47Z | 2019-03-26T12:14:03Z | 54056 |
| 609 | *pastehakk_generate* | .{0,1000}pastehakk_generate.{0,1000} | offensive_tool_keyword | pastehakk | perform clipboard poisoning or paste jacking attack | T1115 | T0001 - T0002 - T0005 | N/A | N/A | Phishing | https://github.com/3xploitGuy/pastehakk | 1 | 0 | #linux #content | N/A | 7 | 1 | 56 | 10 | 2020-06-22T01:17:53Z | 2020-06-17T19:32:24Z | 54497 |
| 610 | *payloads_examples*calc.js* | .{0,1000}payloads_examples.{0,1000}calc\.js.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 1 | N/A | N/A | 10 | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 54555 |
| 611 | *payloads_examples*calc.xll* | .{0,1000}payloads_examples.{0,1000}calc\.xll.{0,1000} | offensive_tool_keyword | EmbedInHTML | What this tool does is taking a file (any type of file). encrypt it. and embed it into an HTML file as ressource. along with an automatic download routine simulating a user clicking on the embedded ressource. | T1027 - T1566.001 | TA0005 - TA0002 | N/A | N/A | Phishing | https://github.com/Arno0x/EmbedInHTML | 1 | 1 | N/A | N/A | 10 | 5 | 485 | 119 | 2017-09-27T13:16:06Z | 2017-09-11T07:17:20Z | 54556 |
| 612 | *phish_test.go* | .{0,1000}phish_test\.go.{0,1000} | offensive_tool_keyword | gophish | Open-Source Phishing Toolkit | T1566-001 - T1566-002 - T1566-003 - T1056-001 - T1113 - T1567-001 | TA0002 - TA0003 | N/A | Black Basta | Phishing | https://github.com/gophish/gophish | 1 | 1 | N/A | N/A | 10 | 10 | 12483 | 2528 | 2024-09-23T04:24:43Z | 2013-11-18T23:26:43Z | 54774 |
| 613 | *Phish-Creds.ps1* | .{0,1000}Phish\-Creds\.ps1.{0,1000} | offensive_tool_keyword | phishing-HTML-linter | Phishing and Social-Engineering related scripts | T1566.001 - T1056.001 | TA0040 - TA0001 | N/A | N/A | Phishing | https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing | 1 | 1 | N/A | N/A | 10 | 10 | 2689 | 527 | 2023-06-27T19:16:49Z | 2018-02-02T21:24:03Z | 54776 |
| 614 | *phishDomain = phishDomain +* | .{0,1000}phishDomain\s\=\sphishDomain\s\+.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #content | N/A | 10 | N/A | 54777 | ||||
| 615 | *phishing-HTML-linter.* | .{0,1000}phishing\-HTML\-linter\..{0,1000} | offensive_tool_keyword | phishing-HTML-linter | Phishing and Social-Engineering related scripts | T1566.001 - T1056.001 | TA0040 - TA0001 | N/A | N/A | Phishing | https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing | 1 | 1 | N/A | N/A | 10 | 10 | 2689 | 527 | 2023-06-27T19:16:49Z | 2018-02-02T21:24:03Z | 54778 |
| 616 | *phishlets * | .{0,1000}phishlets\s.{0,1000} | offensive_tool_keyword | gophish | Combination of evilginx2 and GoPhish | T1565-002 - T1565-003 - T1565-012 - T1110 - T1056-001 - T1113 | TA0002 - TA0003 | N/A | Black Basta | Phishing | https://github.com/fin3ss3g0d/evilgophish | 1 | 0 | N/A | N/A | 10 | 10 | 1762 | 340 | 2024-06-15T17:48:11Z | 2022-09-07T02:47:43Z | 54779 |
| 617 | *PhoenixMiner.exe* | .{0,1000}PhoenixMiner\.exe.{0,1000} | greyware_tool_keyword | phoenix miner | Phoenix Miner is a popular. efficient. fast. and cost-effective Ethereum miner with support for both AMD and Nvidia GPUs. It's intended to be used for legitimate cryptocurrency mining purposes.Attackers can secretly install Phoenix Miner on unsuspecting users' computers to mine cryptocurrency for themselves. This is often done by bundling the miner with other software or hiding it within malicious attachments or downloads. The computer then slow down due to the high CPU and GPU usage | T1059.001 - T1057 - T1027 - T1105 - T1064 - T1053.005 - T1089 | TA0002 - TA0005 - TA0011 - TA0040 - TA0003 | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 54782 |
| 618 | *PhoenixMiner_*_Windows\* | .{0,1000}PhoenixMiner_.{0,1000}_Windows\\.{0,1000} | greyware_tool_keyword | phoenix miner | Phoenix Miner is a popular. efficient. fast. and cost-effective Ethereum miner with support for both AMD and Nvidia GPUs. It's intended to be used for legitimate cryptocurrency mining purposes.Attackers can secretly install Phoenix Miner on unsuspecting users' computers to mine cryptocurrency for themselves. This is often done by bundling the miner with other software or hiding it within malicious attachments or downloads. The computer then slow down due to the high CPU and GPU usage | T1059.001 - T1057 - T1027 - T1105 - T1064 - T1053.005 - T1089 | TA0002 - TA0005 - TA0011 - TA0040 - TA0003 | N/A | N/A | Phishing | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 54783 |
| 619 | *php -q -S 0.0.0.0:8111* | .{0,1000}php\s\-q\s\-S\s0\.0\.0\.0\:8111.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/ms101/EvilKnievelnoVNC | 1 | 0 | #linux | N/A | 9 | 1 | 44 | 8 | 2025-03-08T19:34:41Z | 2024-04-13T22:05:04Z | 54790 |
| 620 | *PShlSpy* | .{0,1000}PShlSpy.{0,1000} | signature_keyword | Antivirus Signature | highly revelant Antivirus signature. phishing tools | N/A | N/A | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 55703 |
| 621 | *QNAME*.trycloudfare.com* | .{0,1000}QNAME.{0,1000}\.trycloudfare\.com.{0,1000} | greyware_tool_keyword | trycloudflare.com | The subdomain .trycloudflare.com is a temporary hostname provided by Cloudflare Tunnel - It allows users to expose local services to the internet without needing to configure port forwarding or a public IP - attackers frequently abuse it for malicious activities | T1071.001 - T1090 - T1583.003 - T1102 | TA0001 - TA0005 - TA0008 - TA0011 | N/A | N/A | Phishing | https://www.forcepoint.com/blog/x-labs/asyncrat-python-trycloudflare-malware | 1 | 1 | #dnsquery | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 56150 |
| 622 | *randomalice1986@* | .{0,1000}randomalice1986\@.{0,1000} | offensive_tool_keyword | dnstwist | See what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence. | T1560 - T1565 - T1566 - T1568 - T1569 | TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/elceef/dnstwist | 1 | 1 | email user name | 3 | 10 | 5113 | 801 | 2025-04-15T18:41:47Z | 2015-06-11T12:24:17Z | 56238 | |
| 623 | *randombob1986@* | .{0,1000}randombob1986\@.{0,1000} | offensive_tool_keyword | dnstwist | See what sort of trouble users can get in trying to type your domain name. Find lookalike domains that adversaries can use to attack you. Can detect typosquatters. phishing attacks. fraud. and brand impersonation. Useful as an additional source of targeted threat intelligence. | T1560 - T1565 - T1566 - T1568 - T1569 | TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/elceef/dnstwist | 1 | 1 | email user name | 3 | 10 | 5113 | 801 | 2025-04-15T18:41:47Z | 2015-06-11T12:24:17Z | 56240 | |
| 624 | *reCAPTCHA Verification ID: <span id="verification-id">146820</span>* | .{0,1000}reCAPTCHA\sVerification\sID\:\s\<span\sid\=\"verification\-id\"\>146820\<\/span\>.{0,1000} | offensive_tool_keyword | recaptcha-phish | Phishing with a fake reCAPTCHA | T1566.001 - T1204.002 - T1071.003 | TA0001 - TA0002 | Lumma Stealer | N/A | Phishing | https://github.com/JohnHammond/recaptcha-phish | 1 | 0 | #content | N/A | 10 | 6 | 534 | 104 | 2024-09-13T11:18:29Z | 2024-09-13T07:00:40Z | 56512 |
| 625 | *recaptcha-phish-main.zip* | .{0,1000}recaptcha\-phish\-main\.zip.{0,1000} | offensive_tool_keyword | recaptcha-phish | Phishing with a fake reCAPTCHA | T1566.001 - T1204.002 - T1071.003 | TA0001 - TA0002 | Lumma Stealer | N/A | Phishing | https://github.com/JohnHammond/recaptcha-phish | 1 | 1 | N/A | N/A | 10 | 6 | 534 | 104 | 2024-09-13T11:18:29Z | 2024-09-13T07:00:40Z | 56513 |
| 626 | *ReelPhish* | .{0,1000}ReelPhish.{0,1000} | offensive_tool_keyword | ReelPhish | ReelPhish consists of two components: the phishing site handling code and this script. The phishing site can be designed as desired. Sample PHP code is provided in /examplesitecode. The sample code will take a username and password from a HTTP POST request and transmit it to the phishing script. The phishing script listens on a local port and awaits a packet of credentials. Once credentials are received. the phishing script will open a new web browser instance and navigate to the desired URL (the actual site where you will be entering a users credentials). Credentials will be submitted by the web browser | T1566 - T1114 - T1071 - T1547 - T1546 | TA0001 - TA0003 - TA0008 | N/A | N/A | Phishing | https://github.com/fireeye/ReelPhish | 1 | 0 | N/A | N/A | N/A | 6 | 514 | 153 | 2023-08-11T01:40:07Z | 2018-02-01T20:35:11Z | 56598 |
| 627 | *require 'evil-proxy'* | .{0,1000}require\s\'evil\-proxy\'.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 57145 |
| 628 | *require 'evil-proxy/async'* | .{0,1000}require\s\'evil\-proxy\/async\'.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 57146 |
| 629 | *require 'evil-proxy/store'* | .{0,1000}require\s\'evil\-proxy\/store\'.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 57147 |
| 630 | *RobustPentestMacro* | .{0,1000}RobustPentestMacro.{0,1000} | offensive_tool_keyword | phishing-HTML-linter | Phishing and Social-Engineering related scripts | T1566.001 - T1056.001 | TA0040 - TA0001 | N/A | N/A | Phishing | https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing | 1 | 1 | N/A | N/A | 10 | 10 | 2689 | 527 | 2023-06-27T19:16:49Z | 2018-02-02T21:24:03Z | 57425 |
| 631 | *ryhanson/phishery* | .{0,1000}ryhanson\/phishery.{0,1000} | offensive_tool_keyword | phishery | Phishery is a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication. Phishery also provides the ability easily to inject the URL into a .docx Word document. | T1566.001 - T1071 - T1204.002 | TA0001 | N/A | BERSERK BEAR | Phishing | https://github.com/ryhanson/phishery | 1 | 1 | N/A | N/A | 9 | 10 | 993 | 209 | 2017-09-11T15:42:10Z | 2016-09-25T02:19:24Z | 57805 |
| 632 | *sandeshyadavm46@gmail.com* | .{0,1000}sandeshyadavm46\@gmail\.com.{0,1000} | offensive_tool_keyword | pastehakk | perform clipboard poisoning or paste jacking attack | T1115 | T0001 - T0002 - T0005 | N/A | N/A | Phishing | https://github.com/3xploitGuy/pastehakk | 1 | 0 | #linux #email | N/A | 7 | 1 | 56 | 10 | 2020-06-22T01:17:53Z | 2020-06-17T19:32:24Z | 57931 |
| 633 | *saycheese-master.zip* | .{0,1000}saycheese\-master\.zip.{0,1000} | offensive_tool_keyword | saycheese | Grab target's webcam shots by link | T1213 - T1071 - T1102 - T1123 - T1185 - T1200 | TA0001 - TA0005 - TA0009 - TA0011 | N/A | N/A | Phishing | https://github.com/hangetzzu/saycheese | 1 | 1 | N/A | N/A | 9 | 10 | 1175 | 962 | 2024-06-18T23:39:41Z | 2019-04-29T04:07:00Z | 57940 |
| 634 | *sneaky_gophish* | .{0,1000}sneaky_gophish.{0,1000} | offensive_tool_keyword | gophish | Hiding GoPhish from the boys in blue | T1566-001 - T1566-002 - T1566-003 - T1056-001 - T1113 - T1567-001 | TA0002 - TA0003 | N/A | Black Basta | Phishing | https://github.com/puzzlepeaches/sneaky_gophish/ | 1 | 1 | N/A | N/A | 10 | 2 | 180 | 58 | 2022-12-06T11:58:00Z | 2021-06-24T12:41:54Z | 59789 |
| 635 | *Social Engineer Toolkit* | .{0,1000}Social\sEngineer\sToolkit.{0,1000} | offensive_tool_keyword | social-engineer-toolkit | The Social-Engineer Toolkit is an open-source penetration testing framework designed for social engineering. SET has a number of custom attack vectors that allow you to make a believable attack quickly. SET is a product of TrustedSec. LLC an information security consulting firm located in Cleveland. Ohio. | T1566 - T1059.004 - T1564.001 | TA0001 - TA0002 - TA0007 | N/A | N/A | Phishing | https://github.com/trustedsec/social-engineer-toolkit | 1 | 0 | N/A | N/A | N/A | 10 | 11798 | 2922 | 2024-10-21T15:46:18Z | 2012-12-31T22:01:33Z | 59838 |
| 636 | *ssh -o StrictHostKeyChecking=no -o ServerAliveInterval=60 -R *serveo.net* | .{0,1000}ssh\s\-o\sStrictHostKeyChecking\=no\s\-o\sServerAliveInterval\=60\s\-R\s.{0,1000}serveo\.net.{0,1000} | offensive_tool_keyword | saycheese | Grab target's webcam shots by link | T1213 - T1071 - T1102 - T1123 - T1185 - T1200 | TA0001 - TA0005 - TA0009 - TA0011 | N/A | N/A | Phishing | https://github.com/hangetzzu/saycheese | 1 | 0 | N/A | N/A | 9 | 10 | 1175 | 962 | 2024-06-18T23:39:41Z | 2019-04-29T04:07:00Z | 60135 |
| 637 | *Starting php server at localhost:* | .{0,1000}Starting\sphp\sserver\sat\slocalhost\:.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | #content | N/A | 10 | N/A | 60330 | ||||
| 638 | *TARGET=evilginx* | .{0,1000}TARGET\=evilginx.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #content | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 60912 |
| 639 | *TeamsPhisher.git* | .{0,1000}TeamsPhisher\.git.{0,1000} | offensive_tool_keyword | teamsphisher | Send phishing messages and attachments to Microsoft Teams users | T1566.001 - T1566.002 - T1204.001 | TA0001 - TA0005 | N/A | Black Basta | Phishing | https://github.com/Octoberfest7/TeamsPhisher | 1 | 1 | N/A | N/A | N/A | 10 | 1073 | 138 | 2024-06-19T21:41:55Z | 2023-07-03T02:19:47Z | 61076 |
| 640 | *teamsphisher.log* | .{0,1000}teamsphisher\.log.{0,1000} | offensive_tool_keyword | teamsphisher | Send phishing messages and attachments to Microsoft Teams users | T1566.001 - T1566.002 - T1204.001 | TA0001 - TA0005 | N/A | Black Basta | Phishing | https://github.com/Octoberfest7/TeamsPhisher | 1 | 1 | N/A | N/A | N/A | 10 | 1073 | 138 | 2024-06-19T21:41:55Z | 2023-07-03T02:19:47Z | 61077 |
| 641 | *teamsphisher.py* | .{0,1000}teamsphisher\.py.{0,1000} | offensive_tool_keyword | teamsphisher | Send phishing messages and attachments to Microsoft Teams users | T1566.001 - T1566.002 - T1204.001 | TA0001 - TA0005 | N/A | Black Basta | Phishing | https://github.com/Octoberfest7/TeamsPhisher | 1 | 1 | N/A | N/A | N/A | 10 | 1073 | 138 | 2024-06-19T21:41:55Z | 2023-07-03T02:19:47Z | 61078 |
| 642 | *TeamsPhisher-main.zip* | .{0,1000}TeamsPhisher\-main\.zip.{0,1000} | offensive_tool_keyword | teamsphisher | Send phishing messages and attachments to Microsoft Teams users | T1566.001 - T1566.002 - T1204.001 | TA0001 - TA0005 | N/A | Black Basta | Phishing | https://github.com/Octoberfest7/TeamsPhisher | 1 | 1 | N/A | N/A | N/A | 10 | 1073 | 138 | 2024-06-19T21:41:55Z | 2023-07-03T02:19:47Z | 61079 |
| 643 | *thelinuxchoice/saycheese* | .{0,1000}thelinuxchoice\/saycheese.{0,1000} | offensive_tool_keyword | saycheese | Grab target's webcam shots by link | T1213 - T1071 - T1102 - T1123 - T1185 - T1200 | TA0001 - TA0005 - TA0009 - TA0011 | N/A | N/A | Phishing | https://github.com/hangetzzu/saycheese | 1 | 1 | #linux | N/A | 9 | 10 | 1175 | 962 | 2024-06-18T23:39:41Z | 2019-04-29T04:07:00Z | 61244 |
| 644 | *This is the modified maintained version of Evilginx2. No one will be held responsible for your activities* | .{0,1000}This\sis\sthe\smodified\smaintained\sversion\sof\sEvilginx2\.\sNo\sone\swill\sbe\sheld\sresponsible\sfor\syour\sactivities.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/An0nUD4Y/evilginx2 | 1 | 0 | #content | N/A | 10 | N/A | 61263 | ||||
| 645 | *this.is.not.a.phishing.site.evilsite.com* | .{0,1000}this\.is\.not\.a\.phishing\.site\.evilsite\.com.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #content | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 61265 |
| 646 | *Tunneling failed! Start your own port forwarding/tunneling service at port * | .{0,1000}Tunneling\sfailed!\sStart\syour\sown\sport\sforwarding\/tunneling\sservice\sat\sport\s.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 61711 | ||||
| 647 | *UACBypassConfig.java* | .{0,1000}UACBypassConfig\.java.{0,1000} | offensive_tool_keyword | lnk2pwn | Malicious Shortcut(.lnk) Generator | T1204 - T1059.007 | TA0001 - TA0002 | N/A | N/A | Phishing | https://github.com/it-gorillaz/lnk2pwn | 1 | 0 | N/A | N/A | 8 | 2 | 193 | 34 | 2018-11-23T17:18:49Z | 2018-11-23T00:12:48Z | 61779 |
| 648 | *unzip websites.zip -d sites > /dev/null* | .{0,1000}unzip\swebsites\.zip\s\-d\ssites\s\>\s\/dev\/null.{0,1000} | offensive_tool_keyword | CamHacker | Camera phishing tool. If anyone opens link generated by CamHacker and permits camera access his/her photo will be captured! | T1598 - T1204 - T1566.001 | TA0009 - TA0010 - TA0043 | N/A | N/A | Phishing | https://github.com/KasRoudra/CamHacker | 1 | 0 | N/A | N/A | 10 | N/A | 61921 | ||||
| 649 | *url: 'forwarding_link/post.php',* | .{0,1000}url\:\s\'forwarding_link\/post\.php\',.{0,1000} | offensive_tool_keyword | saycheese | Grab target's webcam shots by link | T1213 - T1071 - T1102 - T1123 - T1185 - T1200 | TA0001 - TA0005 - TA0009 - TA0011 | N/A | N/A | Phishing | https://github.com/hangetzzu/saycheese | 1 | 0 | N/A | N/A | 9 | 10 | 1175 | 962 | 2024-06-18T23:39:41Z | 2019-04-29T04:07:00Z | 61962 |
| 650 | *using ClickJack.Extensions* | .{0,1000}using\sClickJack\.Extensions.{0,1000} | offensive_tool_keyword | clickjack | automate abuse of clickonce applications | T1210 - T1204 - T1071.001 | TA0001 - TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/trustedsec/The_Shelf | 1 | 0 | N/A | N/A | 10 | 3 | 247 | 14 | 2024-11-25T19:33:34Z | 2024-05-22T14:31:52Z | 62074 |
| 651 | *using ClickJack.Modules* | .{0,1000}using\sClickJack\.Modules.{0,1000} | offensive_tool_keyword | clickjack | automate abuse of clickonce applications | T1210 - T1204 - T1071.001 | TA0001 - TA0002 - TA0005 | N/A | N/A | Phishing | https://github.com/trustedsec/The_Shelf | 1 | 0 | N/A | N/A | 10 | 3 | 247 | 14 | 2024-11-25T19:33:34Z | 2024-05-22T14:31:52Z | 62075 |
| 652 | *vba-macro-mac-persistence.vbs* | .{0,1000}vba\-macro\-mac\-persistence\.vbs.{0,1000} | offensive_tool_keyword | phishing-HTML-linter | Phishing and Social-Engineering related scripts | T1566.001 - T1056.001 | TA0040 - TA0001 | N/A | N/A | Phishing | https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing | 1 | 1 | N/A | N/A | 10 | 10 | 2689 | 527 | 2023-06-27T19:16:49Z | 2018-02-02T21:24:03Z | 62128 |
| 653 | *vba-windows-persistence.vbs* | .{0,1000}vba\-windows\-persistence\.vbs.{0,1000} | offensive_tool_keyword | phishing-HTML-linter | Phishing and Social-Engineering related scripts | T1566.001 - T1056.001 | TA0040 - TA0001 | N/A | N/A | Phishing | https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing | 1 | 1 | N/A | N/A | 10 | 10 | 2689 | 527 | 2023-06-27T19:16:49Z | 2018-02-02T21:24:03Z | 62130 |
| 654 | *vil-proxy/quickcert* | .{0,1000}vil\-proxy\/quickcert.{0,1000} | offensive_tool_keyword | evil-proxy | A ruby http/https proxy to do EVIL things | T1557 - T1110.001 - T1563.001 | TA0006 - TA0001 - TA0009 - TA0040 | N/A | N/A | Phishing | https://github.com/bbtfr/evil-proxy | 1 | 0 | N/A | N/A | 9 | 2 | 172 | 96 | 2023-10-30T07:49:40Z | 2015-07-30T01:54:40Z | 62188 |
| 655 | *Wanetty inspired by @JoelGMSec* | .{0,1000}Wanetty\sinspired\sby\s\@JoelGMSec.{0,1000} | offensive_tool_keyword | EvilnoVNC | EvilnoVNC is a Ready to go Phishing Platform | T1566 - T1110 - T1555 - T1204 - T1592 | TA0001 - TA0006 - TA0009 | N/A | N/A | Phishing | https://github.com/JoelGMSec/EvilnoVNC | 1 | 0 | #linux #content | N/A | 9 | 10 | 960 | 169 | 2025-03-04T15:59:27Z | 2022-09-04T10:48:49Z | 62351 |
| 656 | *WMIPersistence.vbs* | .{0,1000}WMIPersistence\.vbs.{0,1000} | offensive_tool_keyword | phishing-HTML-linter | Phishing and Social-Engineering related scripts | T1566.001 - T1056.001 | TA0040 - TA0001 | N/A | N/A | Phishing | https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing | 1 | 1 | N/A | N/A | 10 | 10 | 2689 | 527 | 2023-06-27T19:16:49Z | 2018-02-02T21:24:03Z | 62994 |
| 657 | *X-Evilginx* | .{0,1000}X\-Evilginx.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | N/A | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 63217 |
| 658 | *X-Gophish-Contact* | .{0,1000}X\-Gophish\-Contact.{0,1000} | offensive_tool_keyword | gophish | Gophish is an open-source phishing toolkit designed for businesses and penetration testers. It provides the ability to quickly and easily setup and execute phishing engagements and security awareness training. | T1566 - T1598 | TA0008 - TA0009 | N/A | Black Basta | Phishing | https://github.com/gophish/gophish | 1 | 0 | N/A | N/A | 10 | 10 | 12483 | 2528 | 2024-09-23T04:24:43Z | 2013-11-18T23:26:43Z | 63224 |
| 659 | *xillwillx/tricky.lnk* | .{0,1000}xillwillx\/tricky\.lnk.{0,1000} | offensive_tool_keyword | tricky.lnk | VBS that creates a .lnk file spoofing the file extension with unicode chars that reverses the .lnk file extension. appends .txt to the end and changes the icon to notepad to make it appear as a textfile. When executed. the payload is a powershell webdl and execute | T1027 - T1036 - T1218.010 | TA0002 - TA0003 - TA0008 | N/A | N/A | Phishing | https://github.com/xillwillx/tricky.lnk | 1 | 1 | N/A | N/A | N/A | 2 | 114 | 33 | 2020-12-19T23:42:10Z | 2016-10-26T21:25:06Z | 63229 |
| 660 | *you need to provide the path to directory where your phishlets are stored:* | .{0,1000}you\sneed\sto\sprovide\sthe\spath\sto\sdirectory\swhere\syour\sphishlets\sare\sstored\:.{0,1000} | offensive_tool_keyword | evilginx2 | Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies allowing for the bypass of 2-factor authentication | T1557.002 - T1114 - T1539 | TA0001 | N/A | BlackCat - COLDRIVER - Black Basta | Phishing | https://github.com/kgretzky/evilginx2 | 1 | 0 | #content | N/A | 10 | 10 | 12879 | 2234 | 2025-01-21T15:16:19Z | 2018-07-10T09:59:52Z | 63378 |
| 661 | https://*.xyz/*.ps1 | http.*\.(country|stream|gdn|mom|xin|kim|men|loan|download|racing|online|science|ren|gb|win|top|review|vip|party|tech|xyz|date|faith|cricket|space|info|vn|cm|am|cc|asia|ws|tk|biz|su|st|ge|pk|nu|me|ph|to|tt|name|tv|kz|tc|mobi|study|click|link|trade|accountant|cf|gq|ml|ga|pw)\/.*\.(exe|vbs|bat|rar|ps1|doc|docm|xls|xlsm|pptm|rtf|hta|dll|ws|wsf|sct|zip|bin)$ | greyware_tool_keyword | _ | Suspicious tlds with suspicious file types | T1204 - T1212 - T1562 | TA0001 - TA0003 - TA0005 | N/A | N/A | Phishing | N/A | 0 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 63564 |
| 662 | */invoices.hta* | .{0,1000}\/invoices\.hta.{0,1000} | greyware_tool_keyword | _ | suspicious file name often used by attackers in phishing attempts (threat hunting only) | T1059.005 - T1204.002 | TA0002 - TA0001 | N/A | N/A | Phishing | N/A | 0 | 1 | N/A | N/A | 6 | 8 | N/A | N/A | N/A | N/A | 63718 |