Skip to content
KitploitKITPLOIT
FerramentasBlog
Enviar
FerramentasBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
Evilginx-Phishing-Infra-Setup — Guia de Configuração da Infraestrutura de Phishing do Evilginx - Protegendo a Infraestrutura do Evilginx e do Gophish, Removendo IOCs, TTPs de Phishing | Kitploit
Ferramentas/GitHubGitHub/an0nud4y/evilginx-phishing-infra-setup
Ferramentas de PhishingEvasão de IDS/IPSPhishingComando e ControleEngenharia SocialAprendizado e EducaçãoRed TeamingRecursos CuradosSegurança de Email

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar
GitHuban0nud4y/evilginx-phishing-infra-setup

Evilginx-Phishing-Infra-Setup

Guia de Configuração da Infraestrutura de Phishing do Evilginx - Protegendo a Infraestrutura do Evilginx e do Gophish, Removendo IOCs, TTPs de Phishing

Ver Repositório
598115há 1 anoRevisado pelo Kitploit

Guia de Configuração de Infraestrutura para Campanhas de Phishing

Nota: Estas são cópias das minhas notas pessoais. Por favor, não dependa totalmente delas.

Índice

  • Blogs/Palestras
  • Automação de Infraestrutura de Red Team/Phishing
  • Técnicas de Compra e Categorização de Domínios
  • Melhore a Escrita de E-mails de Phishing Usando Ferramentas
  • Teste a Probabilidade de Spam do E-mail
  • Simule E-mails de Phishing / Phishing para Purple Team
  • Incrível Segurança de E-mail Corporativo
  • Entrega de E-mails na Caixa de Entrada
  • Campanhas de Phishing com Evilginx
    • Criação de Phishlets do Evilginx
    • Scripts de Instalação do Evilginx
    • Dicas de Segurança para Infraestrutura Evilginx
    • Blogs/Palestras de Pesquisa sobre Evilginx
    • Táticas de Defesa Contra o Evilginx
  • Protegendo a Infraestrutura do GoPhish
    • Blogs/Palestras de Pesquisa sobre GoPhish
    • Alternativas ao Gophish
  • Blogs/Palestras de Pesquisa sobre Pós-exploração de AiTM / Phishing
  • Outras Técnicas/Blogs/Pesquisas
  • Palestras de Pesquisa sobre Phishing

Blogs/Palestras

  • BHIS | Como Construir um Engajamento de Phishing - Codificando TTPs : https://m.youtube.com/watch?si=YTjMa8XBusj_tPdc&v=VglCgoIjztE&feature=youtu.be

Automação de Infraestrutura de Red Team/Phishing

  • https://github.com/dazzyddos/HSC24RedTeamInfra/blob/main/RedTeamInfraAutomation.pdf
  • OFFENSIVEX 2024 - Vincent Yiu - Dicas de Red Team em 2024 : https://youtu.be/ECIBCbMfeo4?feature=shared
  • https://github.com/bluscreenofjeff/Red-Team-Infrastructure-Wiki
  • Implante uma infraestrutura de phishing on the fly : https://github.com/VirtualSamuraii/flyphish
  • https://labs.jumpsec.com/putting-the-c2-in-c2loudflare/

Técnicas de Compra e Categorização de Domínios

  • Verifique domínios expirados e possivelmente compre os bons

    • https://expireddomains.net/
  • Categorização de Domínios

    • Bluecoat/Symantec - https://sitereview.bluecoat.com/#/
    • McAfee - https://www.trustedsource.org
    • Palo Alto Wildfire - https://urlfiltering.paloaltonetworks.com
    • Websense - https://csi.forcepoint.com & https://www.websense.com/content/SiteLookup.aspx (necessita de registro)
    • FortiGuard - https://www.fortiguard.com/webfilter
    • IBM X-force - https://exchange.xforce.ibmcloud.com
    • Cyren - https://www.cyren.com/security-center/url-category-check-gate
    • Checkpoint - https://www.checkpoint.com/urlcat/main.htm (necessita de registro)
    • Trend Micro - https://global.sitesafety.trendmicro.com/
    • Sophos - https://secure2.sophos.com/en-us/support/contact-support.aspx (apenas envio; sem verificação) (Clique em Submit a Sample -> Web Address)
    • BrightCloud - http://www.brightcloud.com/tools/url-ip-lookup.php
    • LightSpeed Systems - https://archive.lightspeedsystems.com/
  • Automatizando Verificação/Envio de Reputação de Domínios

    • Domainhunter: https://github.com/threatexpress/domainhunter
    • Chameleon : https://github.com/mdsecactivebreach/Chameleon

Melhore a Escrita de E-mails de Phishing Usando Ferramentas

  • mgeeky : https://github.com/mgeeky/Penetration-Testing-Tools/tree/master/phishing
  • HTML-Linter (evite palavras comuns em e-mails de phishing) : https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/phishing/phishing-HTML-linter.py
  • Decode-Spam-Headers : https://github.com/mgeeky/decode-spam-headers

Teste a Probabilidade de Spam do E-mail

  • https://www.mail-tester.com/

Simule E-mails de Phishing / Phishing para Purple Team

  • https://delivr.to/

Incrível Segurança de E-mail Corporativo

  • https://github.com/0xAnalyst/awesome-email-security
  • Gartner Magic Quadrant para Plataformas de Segurança de E-mail email-security-providers

Entrega de E-mails na Caixa de Entrada

  • Método -1 : Usando Provedores de Serviço de E-mail

    • Use SendGrid - http://sendgrid.com/
      • serviço útil, mas honestamente, você precisa do plano Pro pago para ter a sorte de não estar em uma lista de spam
    • MailGun - https://app.mailgun.com/
      • não tive nenhum problema
    • Amazon AWS SES
    • Brevo : https://www.brevo.com/free-smtp-server/
    • Outlook
    • Gmail
    • Configure um locatário do Azure para obter um domínio onmicrosoft.com como attackdomain.onmicrosoft.com, que pode ser usado tanto para envio de e-mails quanto como domínio de phishing
    • LarkSuite (permite domínio personalizado) : https://www.larksuite.com/
    • Zoho (Use a opção de e-mail "Free for Life" do Zoho) : https://www.zoho.com/mail/custom-domain-email.html
    • Yandex : https://360.yandex.com/business/domain-mail/
  • Método - 2 : Técnicas Aleatórias

    • Técnica 1 : Por Andre Rosario - Do Discord BreakDev Red

      • Se você estiver tendo problemas para entregar e-mails devido à filtragem de e-mail, considere usar o Microsoft 365 e o Azure IPP para enviar e-mails criptografados aos seus alvos!
        • Os e-mails se originam de servidores SMTP legítimos da Microsoft, então eles não podem bloqueá-los.
        • Os alvos que recebem o e-mail criptografado são os únicos que podem abri-lo; se o encaminharem para o DFIR, terão que fazer login como esse usuário até mesmo para ver sua mensagem.
        • Orquestração fácil no portal de administração da Microsoft para domínios personalizados; crie muitas contas falsas.
        • O M365 permite definir nomes de exibição arbitrários. Assim, no Outlook do alvo, o e-mail pode parecer que é de [email protected], mas na verdade é de (pessoas técnicas conseguem descobrir isso facilmente)

Campanhas de Phishing com Evilginx

  • Criação de Phishlets do Evilginx

    • Curso de Especialização em Evilginx : https://academy.breakdev.org/evilginx-mastery
    • Documentação do Evilginx : https://help.evilginx.com/
    • Coleções de Phishlets do Evilginx : https://github.com/An0nUD4Y/Evilginx2-Phishlets
    • Técnicas Menos Conhecidas do Evilginx : https://github.com/An0nUD4Y/Evilginx2-Phishlets?tab=readme-ov-file#some-less-known-techniques
  • Scripts de Instalação do Evilginx

    • https://gist.github.com/dunderhay/d5fcded54cc88a1b7e12599839b6badb
  • Dicas de Segurança para Infraestrutura Evilginx -

    • https://github.com/An0nUD4Y/Evilginx2-Phishlets#securing-evilginx-infra-tips

      root@kitploit:~
      - Rewrite URLs on Phishing Pages to avoid detection through URL Path pattern matching (by Kuba).
      - Remove IOCs (X-Evilginx header and Default Cert Details)
      - Modify Unauth redirect static contents
      - Modify code to request wildcard certificates for root domain from Let'sEncrypt other than requesting for each subdomains (As mentioned in Kuba's blog) - Check this repo for reference https://github.com/ss23/evilginx2
      - Put evilginx behind a proxy to help against TLS fingerprinting (JA3 and JA3S)
      - Use cloudflare in between if possible/feasible (You have to configure the SSL Settings correctly, change it to Full in cloudflare settings)
      - Use some known ASN blacklist to avoid getting detected like here (https://github.com/aalex954/evilginx2-TTPs#ip-blacklist)
      - Reduce the Number of proxyhosts in phishlet if possible to reduce content loading time.
      - Host Evilginx at Azure and use their domain (limit proxy host in phishlet to 1 or find a way , may be create multiple azure sub domains and try with that)
      - Add some sub_filters to modify the content of the pages to avoid content based detections, like (Favicon, form title font or style, or anything which seems relevant)
      - Block the feedback/telemetry/logs/analytics subdomains using the phishlet sub_filters which can log the domain or may help later on analysis.
      - See if js-injected is static or dynamic , if static modify the evilginx js-inject code to create dynamic/obfuscated version of your js for each user/target.
      - Make sure to not leak your Evilginx infra IP, Check the DNS history to make sure its not stored anywhere (Analysts may look for older DNS Records of the domain)
      - Be aware of this research : https://catching-transparent-phish.github.io/catching_transparent_phish.pdf , repo - https://catching-transparent-phish.github.io/
      

Blogs/Palestras de Pesquisa sobre Evilginx :

  • Um mar calmo nunca formou um phisherman habilidoso - Kuba Gretzky (x33fc0n 2024) :
    • Palestra : https://youtu.be/Nh99d3YnpI4?si=Ltwus2PS0z97gf2R
    • Slides : https://github.com/kgretzky/talks/blob/main/2024/x33fcon/a-smooth-sea-never-made-a-skilled-phisherman.pdf
  • A triforce do acesso inicial : https://trustedsec.com/blog/the-triforce-of-initial-access
    • Bobber : https://github.com/Flangvik/Bobber
  • Contornando a detecção de AiTM do Canary : https://insights.spotit.be/2024/06/03/clipping-the-canarys-wings-bypassing-aitm-phishing-detections/
  • Proteja o Evilginx usando cloudflare e ofuscação de HTML : https://www.jackphilipbutton.com/post/how-to-protect-evilginx-using-cloudflare-and-html-obfuscation
  • (Melhore a confiança de entrega de e-mail do Evilginx) Adicionando registros SPF, DMARC, DKIM, MX : https://fortbridge.co.uk/research/add-spf-dmarc-dkim-mx-records-evilginx/
    • https://m3rcer.netlify.app/redteaming/spamfilterbypass/
  • Táticas de phishing e OPSEC : https://mgeeky.tech/uploads/WarCon22 - Modern Initial Access and Evasion Tactics.pdf
  • Evilginx + BITB + Táticas de evasão : https://youtu.be/p1opa2wnRvg
  • Hook, Line and Phishlet - Conquistando o AD FS com o Evilginx : https://research.aurainfosec.io/pentest/hook-line-and-phishlet/
  • Infraestrutura de Phishing O365 - https://badoption.eu/blog/2023/12/03/PhishingInfra.html
  • You Can’t See Me – Protegendo Sua Infraestrutura de Phishing :

Táticas de Defesa contra o Evilginx

  • Desvendando e combatendo o phishing com adversário no meio - X33fcon 2024 - https://youtu.be/-W-LxcbUxI4
  • Usando HoneyTokens para detectar AiTM : https://zolder.io/using-honeytokens-to-detect-aitm-phishing-attacks-on-your-microsoft-365-tenant/
  • Proteja-se contra phishing moderno : https://bleekseeks.com/blog/how-to-protect-against-modern-phishing-attacks
  • https://www.youtube.com/watch?v=wTLB0Yh70_0
  • Detectando o evilginx usando impressões digitais JA3, JA3S, JA4
    • Banco de dados JA4 : https://ja4db.com/

Protegendo a Infra do GoPhish

Essas modificações também funcionarão na versão mais recente do evilginx + gophish, ou seja, evilginx3.3

  • Dicas : Use o parâmetro {{.URL}} no template de phishing ao usar com o evilginx ( https://github.com/kgretzky/evilginx2/issues/1042#issuecomment-2052073864)

  • Modificações no código-fonte e na estrutura de arquivos do gophish para proteger a Infra do GoPhish

    • Remova as instâncias de X-Gophish ( X-Gophish-Contact , X-Gophish-Signature)

    • Remova const ServerName= "gophish" e altere para const ServerName= "IGNORE" no arquivo config/config.go

    • Altere a porta padrão do servidor Admin no arquivo config.json.

    • Modifique as Assinaturas de Mensagens de E-mail de Teste para evitar detecção durante testes SMTP. Controllers > api > util.go

      root@kitploit:~
      Controllers > api > util.go
      models > testdata > email_request.go
      models > testdata > email_request_test.go
      models > testdata > maillog.go
      models > testdata > maillog_test.go
      models > testdata > smtp_test.go
      

Blogs/Palestras de Pesquisa sobre Pós-Exploração de AiTM / Phishing

  • AiTm (Pós-exploração) : https://www.youtube.com/live/WY4mH-8TbWY?si=LkZ1LuduDln1vRuj
    • https://youtu.be/py68OE4tQ4Q?si=n6QlNuro88c1PRzn
  • https://trustedsec.com/blog/the-triforce-of-initial-access
  • https://www.youtube.com/live/tOzURCc-qUc?si=DMkLwXHVQomRMEJD## Outras Técnicas/Blogs/Pesquisas
  • Para abusar de sites legítimos para phishing : https://lots-project.com/
  • Muraena : https://github.com/muraenateam/muraena
  • NecroBrowser : https://github.com/muraenateam/necrobrowser
  • BITB : https://mrd0x.com/browser-in-the-browser-phishing-attack/
    • Frameless-bitb : https://github.com/waelmas/frameless-bitb
      • https://youtu.be/luJjxpEwVHI?si=sk8kMfdfhZbTz8qR
    • CuddlePhish : https://github.com/fkasler/cuddlephish
    • https://pushsecurity.com/blog/phishing-2-0-how-phishing-toolkits-are-evolving-with-aitm/
    • Okta encadeado com Azure com inscrição automática de MFA para Okta e bypass do Frame Buster para realizar BITB : https://x.com/otterhacker/status/1929487165458641045?s=46&t=mlJvZy0Zrkrxzuvtt7m2cQ
      • https://github.com/OtterHacker/OktaGinx/
  • Phishing com Progressive Web Apps (PWA) : https://mrd0x.com/progressive-web-apps-pwa-phishing/
  • Phishing com noVNC : https://adepts.of0x.cc/novnc-phishing/

Palestras sobre Pesquisa em Phishing

  • https://youtu.be/zmo_tPbCXtA?si=4imjZtwQ6I9iu_tP
Baixar ferramenta
  • Blogs

    • https://medium.com/@frsfaisall/mastering-modern-red-teaming-infrastructure-leveraging-old-domains-for-reputation-based-bypasses-1fd8cc1768f7
  • [email protected]
  • Os e-mails vêm de IPs e domínios legítimos da Microsoft, então você não precisa se preocupar com categorização de domínio ou tempo de vida, já que é da Microsoft.
  • Técnica 2 : Usando a funcionalidade de Convite Externo do Azure - Do Discord BreakDev Red

    • O Convite Externo do Azure pode ser usado para enviar um e-mail com link de redirecionamento para URL de phishing
    • E-mails em massa também podem ser enviados; para referência, verifique: https://learn.microsoft.com/en-us/entra/external-id/tutorial-bulk-invite
  • Dicas aleatórias para ajudar a colocar e-mails na caixa de entrada.

    • Tenha um domínio com boa reputação; verifique a categorização do domínio
    • Tenha um domínio com mais de 1 ano ou use expireddomain
    • Tenha DKIM, DMARC e SPF válidos.
      • Mailgoose (verifica se a configuração de SPF, DMARC e DKIM está correta) : https://github.com/CERT-Polska/mailgoose
    • Adicione link de descadastramento no e-mail
    • Envie e-mails benignos primeiro (pode ajudar com a reputação)
    • Tenha no e-mail um link com o mesmo domínio usado para enviar o e-mail.
  • Blogs/Palestras/Referências

    • Outlook_Email_Auth_Bypass : https://gitlab.com/hxxpxxp/outlook_email_auth_bypass (No Outlook para desktop e no aplicativo web, o "nome de exibição" do cabeçalho "De" do e-mail pode manipular o remetente exibido ao usuário, o que pode resultar em e-mails de phishing mais convincentes)
    • Spy Pixel - Pixel de Imagem para rastrear e-mails : https://github.com/collinsmc23/spy-pixel
    • EchoSpoofing : https://labs.guard.io/echospoofing-a-massive-phishing-campaign-exploiting-proofpoints-email-protection-to-dispatch-3dd6b5417db6
    • Blackhat USA 2024 - Novos Padrões de Ataque de Spoofing de E-mail : https://github.com/onhexgroup/Conferences/blob/main/Black Hat USA 2024 slides/Hao Wang %26 Caleb Sargent %26 Harrison Pomeroy %26 Renana Friedlich_Into the Inbox Novel Email Spoofing Attack Patterns.pdf
  • Remova o cabeçalho X-Evilginx (verifique todas as linhas de código com req.Header.Set e comente as funções relevantes no arquivo core/http_proxy.go)

    root@kitploit:~
      // comment line 469
      req.Header.Set(p.getHomeDir(), o_host)
      
      //comment line 659
      req.Header.Set(p.getHomeDir(), o_host)
      
      // comment function at line 1791-1793
      func (p *HttpProxy) getHomeDir() string {
      	return strings.Replace(HOME_DIR, ".e", "X-E", 1)
      }
      
      // comment line 52-54
      const (
      	HOME_DIR = ".evilginx"
      )
    
  • Para modificar os conteúdos estáticos de redirecionamento não autenticado, pesquise por <html> no arquivo core/http_proxy.go e modifique o código html para remover quaisquer assinaturas estáticas.

  • Além disso, para evitar a detecção de assinatura do código js injetado estático, você pode modificar o código como abaixo

    • Certifique-se de adicionar "github.com/tdewolff/minify/js" em imports

      root@kitploit:~
      	re := regexp.MustCompile(`(?i)(<\s*/body\s*>)`)
      	var d_inject string
      
      	if script != "" {
      		minifier := minify.New() // "github.com/tdewolff/minify/js"
      		minifier.AddFunc("text/javascript", js.Minify)
      		obfuscatedScript, err := minifier.String("text/javascript", script)
      		if err != nil {
      			// Handle error - Obfuscation failed
      			d_inject = "<script" + js_nonce + ">" + "function doNothing() {var x =0};" + script + "</script>\n${1}"
      		}
      		d_inject = "<script" + js_nonce + ">" + "function doNothing() {var x =0};" + obfuscatedScript + "</script>\n${1}"
      		//d_inject = "<script" + js_nonce + ">" + "function doNothing() {var x =0};" + script + "</script>\n${1}"
      
      	} else if src_url != "" {
      		d_inject = "<script" + js_nonce + " type=\"application/javascript\" src=\"" + src_url + "\"></script>\n${1}"
      	} else {
      		return body
      	} 
      
  • Modifique também o arquivo core/cert.db

  • Altere “rid” para o gophish.

  • Use nginx, caddy ou outros proxies na frente do evilginx.

  • Use Redirecionadores

    • Use o cloudflare turnstile como redirecionador do evilginx e bloqueie bots.
      • https://github.com/kgretzky/evilginx2/blob/master/redirectors/turnstile/index.html
    • Ofusque redirecionadores baseados em html/js
      • Lista de User Agents HTTP suspeitos : https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_http_user_agents_list.csv
      • https://github.com/DosX-dev/WebSafeCompiler
    • Métodos de detecção de bots usados pelo kit de phishing gabagool : https://medium.com/@traclabs_/aitm-phishing-hold-the-gabagool-analyzing-the-gabagool-phishing-kit-531f5bbaf0e4
    • Tag html Meta para redirecionamento
      • <meta http-equiv="refresh" content="5;url=https://example.com">
  • Altere o padrão padrão de URL do lure, que é uma string aleatória de comprimento 8.

    root@kitploit:~
       // Line 728 in core/terminal.go file
      		l := &Lure{
      			Path:     "/" + GenRandomString(8),
      			Phishlet: args[1],
      		}
    
  • Reescreva URLs nas páginas de phishing para evitar detecção por correspondência de padrões de caminho de URL (por Kuba). [Este recurso não está disponível na versão pública do evilginx; você precisa implementá-lo você mesmo.]

    root@kitploit:~
    # Only Work in Evilginx Pro Version
    # Similar functionality can be implemented in public version as well.
    rewrite_urls:
    
    trigger:
    domains: ['www.linkedin.com']
    paths: ['^/login$']
    rewrite:
    path: '/this/is/not/the/path/you/are/looking/for.php'
    query:
    
        {key:'a', value: 'HOW'}
        {key:'b', value: 'MUCH'}
        {key:'d', value: 'IS'}
        {key:'e', value: 'THE'}
        {key:'f', value: 'PHISH'}
        {key:'q', value: '{id}'}
    
    

    Untitled

  • Modifique o padrão e o valor assinados dos cookies de identificação de sessão/lure (por @rad9800 )

    • Regra 1: Nome do cookie=XXXX-XXXX e valor=64_hex_chars - https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d#file-index-js-L130
      • Funcionalidade de código responsável no evilginx (Para o nome do cookie) : https://github.com/kgretzky/evilginx2/blob/9e32484719681892945130187ea52737b3d72051/core/http_proxy.go#L1984
      • Funcionalidade de código responsável no evilginx (Para o valor do cookie) : https://github.com/kgretzky/evilginx2/blob/9e32484719681892945130187ea52737b3d72051/core/http_proxy.go#L895
    • Regra 2: Caminho do script=/s/64_hex_chars.js com content-length=0
    • Regra 3: Ambas as Regras 1 e 2 presentes
      • a lógica completa do snippet de blob js está aqui https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d
  • Bloqueie cabeçalhos Referrer para evitar vazar seu nome de domínio de phishing - consulte este blog de pesquisa como referência :

    • Adicione a linha abaixo no arquivo http_proxy.go aqui (o Chrome não respeita isso e quando a requisição é iniciada pela função CSS url() - consulte o blog para mais detalhes)
      • resp.Header.Set("Referrer-Policy", "no-referrer")
      • Para automatizar via phishlet, verifique este PR: https://github.com/kgretzky/evilginx2/pull/1006
  • Defina sua própria CSP (Content Security Policy) para evitar telemetria/canary/detecção por vazamento do domínio de phishing.

    • Leia isto para mais informações: https://insights.spotit.be/2024/06/03/clipping-the-canarys-wings-bypassing-aitm-phishing-detections/
  • Verifique se o site alvo está usando algum tipo de token canário (CSS, JS) e evite-os

    • Contornando a detecção de Canary AiTM (CSS, JS): https://insights.spotit.be/2024/06/03/clipping-the-canarys-wings-bypassing-aitm-phishing-detections/
    • https://blog.thinkst.com/2024/01/defending-against-the-attack-of-the-cloned-websites.html
  • Evasão de fingerprint JA4

    • https://github.com/refraction-networking/utls
    • https://github.com/juzeon/spoofed-round-tripper
  • BITB + evilginx + bypass de frame busting

    • https://x.com/otterhacker/status/1929487165458641045?s=46&t=mlJvZy0Zrkrxzuvtt7m2cQ
      • OktaGinx : https://github.com/OtterHacker/OktaGinx/blob/main/okta.yaml#L17
    • https://github.com/waelmas/frameless-bitb
    • Exemplo de Subfilter de bypass de frame busting de : https://github.com/OtterHacker/OktaGinx/blob/44fed02954b6cd65e17ab581209a4d0f3b734c24/okta.yaml#L124 e https://github.com/OtterHacker/OktaGinx/blob/44fed02954b6cd65e17ab581209a4d0f3b734c24/okta.yaml#L82
      root@kitploit:~
      - triggers_on: 'login.microsoftonline.com'
      orig_sub: ''
      domain: 'okta.com'
      search: 'if\(e.self===e.top\){'
      replace: 'if(true){window.oldself=e.self;e.self=e.top;'
      mimes: ['text/html', 'charset=utf-8']- triggers_on: 'login.microsoftonline.com'
      orig_sub: ''
      domain: 'okta.com'
      search: 'X-Frame-Options: DENY'
      replace: 'Test: test'
      mimes: ['text/html', 'charset=utf-8']
      
      • Técnicas de Frame Busting geralmente usadas
        • https://en.wikipedia.org/wiki/Framekiller
        • https://seclab.stanford.edu/websec/framebusting/framebust.pdf
          • Técnicas comuns para detectar a presença de iframe
            root@kitploit:~
              if (top != self)
              if (top.location != self.location)
              if (top.location != location)
              if (parent.frames.length > 0)
              if (window != top)
              if (window.top !== window.self)
              if (window.self != window.top)
              if (parent && parent != window)
              if (parent && parent.frames && parent.frames.length>0)
              if((self.parent&&!(self.parent===self))&&(self.parent.frames.length!=0))
            
          • Os sites podem usar o seguinte método para realizar o redirecionamento quando um iframe for detectado
            root@kitploit:~
            top.location.replace(self.location)
             top.location.href = window.location.href
             top.location.replace(document.location)
             top.location.href = window.location.href
             top.location.href = "URL"
             document.write(’’)
             top.location = location
             top.location.replace(document.location)
             top.location.replace(’URL’)
             top.location.href = document.location
             top.location.replace(window.location.href)
             top.location.href = location.href
             self.parent.location = document.location
             parent.location.href = self.document.location
             top.location.href = self.location
             top.location = window.location
             top.location.replace(window.location.pathname)
             window.top.location = window.self.location
             setTimeout(function(){document.body.innerHTML=’’;},1);
             window.self.onload = function(evt){document.body.innerHTML=’’;}
             var url = window.location.href; top.location.replace(url)
            
  • https://redsiege.com/blog/2024/01/you-cant-see-me-protecting-your-phishing-infrastructure/
  • https://janbakker.tech/evilginx-resources-for-microsoft-365/
  • Evilginx + BITB - https://www.youtube.com/watch?v=luJjxpEwVHI&feature=youtu.be
  • Hook, Line and Sinker: Phishing do Windows Hello for Business usando Evilginx : https://medium.com/@yudasm/bypassing-windows-hello-for-business-for-phishing-181f2271dc02
  • Phishing contra os resistentes - Phishing para o token de atualização primário no Microsoft Entra por Dirk Jan : https://youtu.be/tNh_sYkmurI?si=qcb917IB5zHU1fQk
  • X33fcon 2024 - https://youtu.be/Nh99d3YnpI4?si=Ltwus2PS0z97gf2R
  • Como atirar em phish num barril - Contornando rastreadores de links : ****https://posts.specterops.io/like-shooting-phish-in-a-barrel-926c1905bb4b
  • Beba como um Phish - Como fazer seus sites de phishing se camuflarem ****: https://posts.specterops.io/drink-like-a-phish-b9e91d0b5677
  • Alimentando os Phishes : ****https://posts.specterops.io/feeding-the-phishes-276c3579bba7
  • https://posts.specterops.io/phish-out-of-water-aaeb677a5af3
  • https://youtu.be/6jYZQKDlKco?si=cpfd4tWQ4V8ZAZaI
  • https://posts.specterops.io/one-phish-two-phish-red-teams-spew-phish-1a2f02010ed7
  • Detecção de ferramentas de phishing da Push Security : https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d
    • A extensão do Chrome da Push Security detecta o evilginx com algumas regras bastante frágeis
      • Regra 1: Cookie name=XXXX-XXXX & value=64_hex_chars
      • Regra 2: Script path=/s/64_hex_chars.js with content-length=0
      • Regra 3: Tanto a Regra 1 quanto a Regra 2 presentes
      • a lógica completa do snippet JS (blob) está aqui https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d
  • https://janbakker.tech/evilginx-loves-temporary-access-passes-too/
  • Altere a resposta 404

    • Adicione a função personalizada abaixo no arquivo controllers/phish.go

      root@kitploit:~
      func customNotFound(w http.ResponseWriter, r *http.Request) {
      	http.Error(w, "Try again!", http.StatusNotFound)
      }
      
    • Agora substitua todas as instâncias de http.NotFound(w, r) por customNotFound(w, r)

  • Remova a resposta hardcoded do robots.txt e modifique-a no arquivo controllers/phish.go

    • Modifique o respectivo código no arquivo phish.go para o abaixo.

      root@kitploit:~
      //Modified Response
      // RobotsHandler prevents search engines, etc. from indexing phishing materials
      func (ps *PhishingServer) RobotsHandler(w http.ResponseWriter, r *http.Request) {
      	fmt.Fprintln(w, "User-agent: *\nDisallow: /*/*\nDisallow: /.git/*")
      }
      
  • Modifique o parâmetro GET "rid" nas requisições

    • Certifique-se de modificar todas as instâncias de "rid" para outra coisa.
    • Elas também estão presentes no código-fonte do evilginx3.3, portanto, certifique-se de modificá-las também.
  • Para prevenções avançadas, você também pode modificar a pasta estática e renomeá-la para outra coisa, além de renomear os arquivos dentro dela para evitar detecção baseada em caminho. Apenas não se esqueça de modificar também o código-fonte relevante.

    • Como nomes de imagens, por exemplo : pixel.png, modifique-o para outra coisa.
  • Altere as Propriedades do Certificado no arquivo util/util.go

    root@kitploit:~
    	template := x509.Certificate{
    		SerialNumber: serialNumber,
    		Subject: pkix.Name{
    			//Organization: []string{"Gophish"},
    			Organization: []string{"Microsoft Corporation"},
    		},
    
  • Use Nginx para fazer proxy do tráfego e evitar qualquer fingerprint de servidor Golang

    • service nginx start

    • Você precisa alterar o config.json do gophish para mudar as portas de http de 80 para 8080 e https da padrão para 60002, conforme mostrado abaixo

      root@kitploit:~
      {
      	"admin_server": {
      		"listen_url": "127.0.0.1:60002",
      		"use_tls": true,
      		"cert_path": "gophish_admin.crt",
      		"key_path": "gophish_admin.key",
      		"trusted_origins": []
      	},
      	"phish_server": {
      		"listen_url": "127.0.0.1:8080",
      		"use_tls": false,
      		"cert_path": "example.crt",
      		"key_path": "example.key"
      	},
      	"db_name": "sqlite3",
      	"db_path": "gophish.db",
      	"migrations_prefix": "db/db_",
      	"contact_address": "",
      	"logging": {
      		"filename": "",
      		"level": ""
      	}
      }
      
    • A configuração abaixo bloqueará todas as requisições com user agent contendo “Bot” ou “bot”

      root@kitploit:~
      # /etc/nginx/nginx.conf
      
      events {
          # Define event processing parameters here
          worker_connections 1024; # Adjust according to your requirements
      }
      
      http {
      
          upstream backend {
              server localhost:8080;
          }
          # HTTP server
          server {
              listen 80 default_server;
              
      
              # Reject requests with "bot" or "Bot" in User-Agent
              if ($http_user_agent ~* (bot|Bot)) {
                  return 403;
              }
      
              location / {
                  proxy_pass http://backend;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto $scheme;
              }
          }
      
          upstream backend_https {
              server localhost:60002;
          }
          # HTTPS server
          server {
              listen 60001 ssl default_server;
      
              ssl_certificate /root/Phishing/gophish-mod/gophish_admin.crt;
              ssl_certificate_key /root/Phishing/gophish-mod/gophish_admin.key;
      
              # Reject requests with "bot" or "Bot" in User-Agent
              if ($http_user_agent ~* (bot|Bot)) {
                  return 403;
              }
      
              location / {
                  proxy_pass https://backend_https;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto $scheme;
              }
          }
      }
      
      
    • Para permitir apenas um user agent específico, use a configuração abaixo. Ela bloqueará todas as requisições e permitirá apenas requisições com user agent “iamdevil”.

      root@kitploit:~
      # /etc/nginx/nginx.conf
      
      events {
          # Define event processing parameters here
          worker_connections 1024; # Adjust according to your requirements
      }
      
      http {
      
          upstream backend {
              server localhost:8080;
          }
      
          # HTTP server
          server {
              listen 80 default_server;
      
              # Reject requests with user agent other than "iamdevil"
              if ($http_user_agent != "iamdevil") {
                  return 403;
              }
      
              location / {
                  proxy_pass http://backend;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto $scheme;
              }
          }
      
          upstream backend_https {
              server localhost:60002;
          }
      
          # HTTPS server
          server {
              listen 60001 ssl default_server;
      
              ssl_certificate /root/Phishing/gophish-mod/gophish_admin.crt;
              ssl_certificate_key /root/Phishing/gophish-mod/gophish_admin.key;
      
              # Reject requests with user agent other than "iamdevil"
              if ($http_user_agent != "iamdevil") {
                  return 403;
              }
      
              location / {
                  proxy_pass https://backend_https;
                  proxy_set_header Host $host;
                  proxy_set_header X-Real-IP $remote_addr;
                  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                  proxy_set_header X-Forwarded-Proto $scheme;
              }
          }
      }
      
  • Modifique a assinatura do pixel de rastreamento do Gophish para evitar detecção baseada no pixel de rastreamento com assinatura.

  • Altere o padrão de sequência dos cabeçalhos de email do gophish. Isso pode ser usado para detectar o gophish (Da BreakDev Red Community).

  • Configure o PostFix na frente do gophish para remover IOCs e outras detecções e a spamminess dos e-mails, além de remover e corrigir os cabeçalhos.

  • Blogs/Palestras de Pesquisa sobre GoPhish :

    • https://edermi.github.io/post/2021/modding_gophish/
    • https://www.sprocketsecurity.com/resources/never-had-a-bad-day-phishing-how-to-set-up-gophish-to-evade-security-controls
    • https://cyberwarfare.live/wp-content/uploads/2023/08/OPSEC-on-the-High-Seas_-A-Gophish-Adventure.pdf
    • https://www.sprocketsecurity.com/resources/never-had-a-bad-day-phishing-how-to-set-up-gophish-to-evade-security-controls
    • https://github.com/puzzlepeaches/sneaky_gophish
    • https://cybercx.co.nz/blog/identifying-gophish-servers/
    • https://github.com/gophish/gophish/issues/1553#issuecomment-523969887
  • Alternativas ao Gophish :

    • SniperPhish : https://github.com/GemGeorge/SniperPhish
    • Mailcow : https://github.com/mailcow/mailcow-dockerized
    • EvilnoVNC : https://github.com/JoelGMSec/EvilnoVNC
    • MultiEvilnoVNC : https://blog.wanetty.com/blog/tools/multievilnovnc
    • https://fhlipzero.io/blogs/6_noVNC/noVNC.html
    • Delusion (kit baseado em NoVNC) : https://cloud.google.com/blog/topics/threat-intelligence/session-stealing-browser-in-the-middle
    • Detectando NoVNC : https://gist.github.com/rad9800/bb73de360fc07ac544f0bc9faac9082d
  • noVNC e Docker : https://powerseb.github.io/posts/Another-phishing-tool/
    • https://github.com/powerseb/NoPhish
    • https://fhlipzero.io/blogs/6_noVNC/noVNC.html
    • https://github.com/Macmod/YesPhish/tree/patchright-chrome
  • EvilQR - Phishing via QR
    • Gerar QR : https://github.com/Flangvik/QRucible
    • https://badoption.eu/blog/2024/01/08/mobilephish.html
    • QR2Ascii : https://github.com/Jojodicus/qr2eascii
    • https://github.com/kgretzky/evilqr , https://breakdev.org/evilqr-phishing/
    • https://github.com/swagkarna/EvilJack
    • https://techcommunity.microsoft.com/t5/microsoft-security-experts-blog/hunting-for-qr-code-aitm-phishing-and-user-compromise/bc-p/4054850
  • NoPhish (docker e noVNC) : https://github.com/powerseb/NoPhish e https://badoption.eu/blog/2023/07/12/entra_phish.html
  • EvilGoPhish : https://github.com/fin3ss3g0d/evilgophish
  • Smishing : https://blog.shared-video.mov/systematic-destruction-hacking-the-scammers-pt.-2
  • Phishing com CloudFlare Workers
    • TryCloudflare : https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/do-more-with-tunnels/trycloudflare/
    • https://github.com/zolderio/AITMWorker
    • https://gist.github.com/RedTeamOperations/33f245a777c9b322b0466b59d6687f15
    • https://cyberwarfare.live/wp-content/uploads/2023/08/Certified-Red-Team-CredOps-Infiltrator-CRT-COI-1.pdf
  • Phishing com buckets públicos do Cloudflare : https://developers.cloudflare.com/r2/buckets/public-buckets/
    • https://medium.com/trac-labs/aitm-phishing-hold-the-gabagool-analyzing-the-gabagool-phishing-kit-531f5bbaf0e4
  • Open Redirect do Google para phishing
    • https://untrustednetwork.net/en/2024/02/26/google-open-redirect/
    • Open Redirect em (não funciona) : https://googleweblight.com/i?u=m4lici0u5.com
    • Open Redirect : https://www.google.com/url?q=https://m4lici0u5.com
    • Open Redirect : https://business.google.com/website_shared/launch_bw.html?f=https://m4lici0u5.com
    • Mais podem ser encontrados em : https://lots-project.com/
  • https://blog.delivr.to/delivr-tos-top-10-payloads-dec-24-pastejacking-image-less-qr-codes-and-concatenated-zip-a32e668106dd#878d
  • Phishing contornando os controles de proteção de e-mail usando Azure Information Protection
    • https://youtu.be/tHNi5BzScVo?si=H2czog19AmTp_O26
    • https://youtu.be/EYUp_MNtJIk?si=sg_9RQggDvqOSLNL
    • https://youtu.be/KhdzIPPW4W0?si=E4CmWx0iO8EaR6JF
  • https://nicolasuter.medium.com/aitm-phishing-with-azure-functions-a1530b52df05
  • https://pushsecurity.com/blog/a-new-class-of-phishing-verification-phishing-and-cross-idp-impersonation/
  • https://blog.delivr.to/delivr-tos-top-10-payloads-dec-24-pastejacking-image-less-qr-codes-and-concatenated-zip-a32e668106dd#878d
  • https://trustedsec.com/blog/oops-i-udld-it-again
  • Phishing de credenciais por abuso do Docusign : https://sublime.security/blog/living-off-the-land-credential-phishing-via-docusign-abuse/
  • Phishing oculto de credenciais com anexos EML : https://sublime.security/blog/hidden-credential-phishing-within-eml-attachments/
  • https://sublime.security/blog/talking-year-end-credential-phishing-scams-over-turkey/
  • Usando o Microsoft Customer Voice para phishing : https://cofense.com/blog/microsoft-customer-voice-urls-used-in-latest-phishing-campaign
  • https://www.youtube.com/live/tOzURCc-qUc?si=DMkLwXHVQomRMEJD
  • DoubleClickJacking : https://www.paulosyibelo.com/2024/12/doubleclickjacking-what.html
    • https://safetyscience.info/labs/doubleclickjacking/
  • Comparação de várias técnicas : https://blog.quarkslab.com/technical-dive-into-modern-phishing.html
  • https://cloud.google.com/blog/topics/threat-intelligence/session-stealing-browser-in-the-middle
  • Abusando de webhooks de entrada do Microsoft Teams para phishing : https://www.blackhillsinfosec.com/wishing-webhook-phishing-in-teams/
    • https://www.youtube.com/live/kMMZrd9intI?si=rd_EKWmXeKbbGAEI
  • Rogue RDP ou RDP (.rdp) para phishing : https://github.com/GoSecure/pyrdp
    • https://cloud.google.com/blog/topics/threat-intelligence/windows-rogue-remote-desktop-protocol
    • https://www.blackhillsinfosec.com/rogue-rdp-revisiting-initial-access-methods/
  • https://easydmarc.com/blog/google-spoofed-via-dkim-replay-attack-a-technical-breakdown/
  • SVG para phishing : https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/pixel-perfect-trap-the-surge-of-svg-borne-phishing-attacks/
  • Usando ClickOnce com phishing para acesso inicial : https://www.netspi.com/blog/technical-blog/adversary-simulation/all-you-need-is-one-a-clickonce-love-story/
  • https://denniskniep.github.io/posts/09-device-code-phishing/
  • https://badoption.eu/blog/2025/04/25/github.html
  • https://atticsecurity.com/blog/aitm-for-whfb-persistence/
  • [Obrigatório conferir] Evilworker : https://github.com/Ahaz1701/EvilWorker
    • https://medium.com/@ahaz1701/evilworker-da94ae171249