Skip to content

7. Phishing

7.1 Scripts

Target Script
Gambler System fault (cannot open account / deposit / withdraw) / activate agent (no rake-back) / overseas gambler (cannot add bank card)
Job applicant Send resume → book meeting room → interview software upgrade
Partnership Guild leader / first-hand gambler data / fourth-party payment (low success rate

7.2 Domain Purchase / Watering-Hole Setup

Domain selection: Expireddomains.com (typo/unicode) / Unicode character list / ditto

SPF bypass: spf / espoofer / swaks / emkei.cz / Mail-Probe / subsidiary self-hosted mail server domain / SendGrid / mailgun

Watering-hole page creation: | Type | Tool/Method | |------|---------| | Chrome phishing | Google Chrome | | Flash phishing | Flash-Pop / FakeFlash | | Customer service system upgrade | XSS → self-built customer service platform → file content parsing (markdown tags) | | Phishing templates | SiteCopy / smalltool / zphisher / EvilnoVNC / evilginx | | Fake Login | fakelogonscreen / SharpLocker / CredsLeaker / Evilginx2-Phishlets / evilginx-collection / Web-Windows-Login-Phishing |

Backend environment setup and anti-sandbox: - OTP: asnphishing - XSS self-hosted platform (cookie not leaked to third parties) - Goblin (modify Flash yourself) - lure (collect email | pair with emailall) - Session-Hijacking-Visual-Exploitation - evilgophish

7.3 Malicious Payload Crafting Methods

Technique Tool/Description
WinRAR self-extracting + CVE-2023-38831 exploit
RLO filename spoofing os.rename('1.exe', '1\u202egnp.exe') / exe→scr/pif
LNK shortcut lnkbomb / Lnk-Trojan / Rocabella / FTPlnk_phishing
File bundling GoFileBinder
CHM easychm + HTML HELP ActiveX: <OBJECT id=x classid="clsid:adb880a6-d8ff-11cf-9377-00aa003b7a11">
ICO replacement BeCyIconGrabber / Resource Hacker / IconsExt
B2E B2E - notepad + chcp 1200 + PowerShell IEX download
Overlong filename -
QR code cli.im/tools
CrossNet CrossNet-Beta - for learning the approach
PDF Bad-Pdf
smuggling BobTheSmuggler