
Scannt Websites auf SocGholish-JavaScript-Injektionen, deobfuskiert schädliche Payloads und meldet Shadowing-Domain-URLs, die in Malvertising-Kampagnen verwendet werden.
Einfaches Skript zum Durchsuchen von Websites nach SocGholish-Injections. Es prüft auf Injections und zeigt sie an, falls gefunden. Außerdem deobfuskiert es und zeigt verschleiernde URL-Domains an.
usage: finder.py [-h] [-url URL] [-ua USER_AGENT] [-f FILENAME] [-p PROXY] [-s]
SocGholish finder
options:
-h, --help show this help message and exit
-url URL URL to check
-ua USER_AGENT, --user-agent USER_AGENT
Specify User-Agent to use with the request
-f FILENAME, --filename FILENAME
csv of domains to check
-p PROXY, --proxy PROXY
Proxy server to use, supported format: http(s)://user:[email protected]
-s, --scripts list all the scripts on the website with their content (useful for debugging or when script doesn't provide correct results)
Standard

NDSX
