From 0c0eb058e8387cca15a86003248d9d03ebb1b75a Mon Sep 17 00:00:00 2001 From: bluscreenofjeff Date: Tue, 8 Aug 2017 00:27:05 -0700 Subject: [PATCH] Added more to the phishing section --- README.md | 39 +++++++++++++++++++++++- images/cobalt-strike-phishing-popup.png | Bin 0 -> 16957 bytes 2 files changed, 38 insertions(+), 1 deletion(-) create mode 100644 images/cobalt-strike-phishing-popup.png diff --git a/README.md b/README.md index 9be15c1..b0683b7 100644 --- a/README.md +++ b/README.md @@ -13,8 +13,10 @@ THANK YOU to all of the authors of the content referenced in this wiki and to al - [Further Resources](#further-resources) - [Domains](#domains) - [Categorization and Blacklist Checking Resources](#categorization-and-blacklist-checking-resources) -- [Phishing](#phishing) +- [Phishing](#phishing-setup) - [Easy Web-Based Phishing](#easy-web-based-phishing) + - [Cobalt Strike Phishing](#cobalt-strike-phishing) + - [Phishing Frameworks](#phishing-frameworks) - [Redirectors](#redirectors) - [SMTP](#smtp) - [Sendmail](#sendmail) @@ -154,6 +156,41 @@ Login to the RoundCube interface with your new user and phish responsibly! ![RoundCube Send Mail](./images/final_phish_away.PNG) +## Cobalt Strike Phishing +Cobalt Strike provides customizable spearphishing functionality to support pentest or red team email phishing. It supports templates in HTML and/or plaintext formats, attachments, a bounceback address, URL embedding, remote SMTP server usage, and per-message send delays. Another interesting feature is the ability to add a unique token to each user's embedded URL for click tracking. + +![Cobalt Strike Spearphishing Popup](/images/cobalt-strike-phishing-popup.png) + +For more detailed information, check out these resources: + +* [Cobalt Strike - Spear Phishing documentation](https://www.cobaltstrike.com/help-spear-phish) +* [Cobalt Strike Blog - What's the go-to phishing technique or exploit?](https://blog.cobaltstrike.com/2014/12/17/whats-the-go-to-phishing-technique-or-exploit/) +* [Spear phishing with Cobalt Strike - Raphael Mudge](https://www.youtube.com/watch?v=V7UJjVcq2Ao) +* [Advanced Threat Tactics (3 of 9) - Targeted Attacks - Raphael Mudge](https://www.youtube.com/watch?v=CxQfWtqpwRs) + + +## Phishing Frameworks + +Beyond rolling your own phishing setup or using a pentest or red teaming fraework, like Cobalt Strike, there are numerous tools and frameworks dedicated to email phishing. While this wiki won't go into detail about each framework, a few resources for each are collected below: + +### Gophish +* [Gophish Official Site](https://getgophish.com/) +* [Gophish GitHub Repo](https://github.com/gophish/gophish) +* [Gophish User Guide](https://www.gitbook.com/book/gophish/user-guide/details) + +### Phishing Frenzy + +* [Phishing Frenzy Official Site](https://www.phishingfrenzy.com/) +* [Phishing Frenzy GitHub Repo](https://github.com/pentestgeek/phishing-frenzy) +* [Introducing Phishing Frenzy - Brandon McCann (@zeknox)](https://www.pentestgeek.com/phishing/introducing-phishing-frenzy) + +### The Social-Engineer Toolkit +* [The Social-Engineer Toolkit GitHub Repo](https://github.com/trustedsec/social-engineer-toolkit) +* [The Social-Engineer Toolkit User Manual](https://github.com/trustedsec/social-engineer-toolkit/raw/master/readme/User_Manual.pdf) + +### FiercePhish (formerly FirePhish) +* [FiercePhish GitHub Repo](https://github.com/Raikia/FiercePhish) +* [FiercePhish Wiki](https://github.com/Raikia/FiercePhish/wiki) # Redirectors diff --git a/images/cobalt-strike-phishing-popup.png b/images/cobalt-strike-phishing-popup.png new file mode 100644 index 0000000000000000000000000000000000000000..f19dc27d251c6b2fbdfc05f1de5000ddfc168caf GIT binary patch literal 16957 zcmch;1z23m)~-7V2}#fp0yLhW2?S}}C0KBGr;*_94#6!zkPZ&P-5r9vySuwP+|F8S z@3r@T_Id98&pqcfJk5lvN!6Uxtap6h7z9d73Zo$6A_4$_BJx>4766{S0|2z1IABHR+jd(k1n>o5ldzIGudB_$_q z@pEfydkdDGi~?>~++)clY<5OGwC=MG4ZpbWoSW=U%H>b)-Xj3O6;L_5{~ZlBigpw1 zjT@c-9?&jZJ!VZF#0wQlmHwO|d+n+j`E%QrvbR*@x@Z$#Dc;~8a z2`IdiB;o~uQIa@0)(M+Nt0`>Gm$z=L__zzI4Vo78P}>@H@n8G)yO*~fM0WK@*RFvA zE!(#AaIw7^)24)|&o5dIFAd97s%HDeZ<~Lg9p0HfZ{Bo!;Le_?S}<|$jQIg1O7{_z z_8zf8%tQcDD3Y|*``zt*qhem-prHY7tUmN5Jm9%`dY$Y&?8up5<5G;S&~Ck!<)h1cMcBQwMXD?wsXuqVmrCCX z+$>V0GTTVV8a1j=-TGYSzHVK^2)&MC7DfhuufvPkeMRM#hZ&vJGx-{YJS1^a;c91Y z6Wg}gst?5$2;X|1^5Hj02x5NqrhM`V@J@M>3Xl2X2__sO94dhRM1U9gEG_*CjxRtK zc=IYJx94(G`8Ls^#$m9RqlzcN%EDfAY;Uh`Af$6ukNzbzRBh<18zF?1T$eo&6#@Qx z%iw0&1KD2Z23YZHHWF=1%B8u zPN>kn{j5QmATfG)r_X1f{3gY`mqdIEqDw)r_0Y6fG`TC81yAwu4dPi5;>t1WlT@rS zeE4Nsc34CF?dzb{`p$Lhmy4bI_C%=9U!0+mM|}QOb2MjOWg6#|8ECAJ zKcGk7j4_$&#S3)u?+vhaHmkiwO8yi{`su|F-yvZiy!mU_Fp(D(B!+q8&fLjc7;YA$ z$_L$i{MddFM&p&-1|%nf96~CYX~r1(Hb;hxJdDr$kHs@JarNm9c3O+{utA{{$&~O12*@|6T+=I zbCzgd4+2R>-0{>L0>QkvGajC*!O9@?PhX_@5JvaykNw6OWe8iBY|B zY{x(}Q4fWV>L1QAEM5;JBsaD=_H}oQcz84wkGHi6V3|0(x}H6=Ff(JSt*9VN0W&g^ zs)y}bf=(pZvSMOlpirEs*_oL+YF=U65w<{L5)u;h8eBZQ)jsv~yjdnFC5dDU*itE` z&YWOWV8O-3#g~9{p}DzvW5WOoG5F=|?Cb;kqahj(C+C(?^^pmQj<&WZZmb5osWp#Z z)%)Z9^99(e<35f(D^gfVX>w^v`{k|Xd0rlsS`H0E!2v}r$?;7A=Z4g$Pv`F>_cgtD zjoR#SXkp`=T$YVt_jIocN}@>9t8HxD183>zI3+DWt*)%5s!IH(Bu4ACnWn@X zvKtNofrf@g1|=r#-O1;pCO^3J;{HX2xiP1-1h=!vcRAho>3i`i1C8Q1v_FMNKunwa z7g5<)1mAc~F9Q#EcjXXB-gg}w6nacfOz1KQ*o9`V>KVK_P3iGQD6gvWC*bnd_+(bH zPK@+EM4L_`iBG;6f8j}d$=&ren;NKsg`J%p(dWELbII%S^75K_tj93zi_WKKOMTPj&<5a7_f}B*Jmyg?6rA!08WOi9uS-D%qn7|i;$YSWH<_@jLDrb|5uU~ig+f{Of z%D1Bgu#dl-_$A{ac6JP{uV*B0^&TIWbZl=M+0U%tiL-KYjuov$v0@qt#~Vbk$iCnw ze}mfIa#uci|A{KiKFI?D;ct3U+m3{h3t!_)zfC}pMpLR>h`qhHC;lirO@YNOQ-Xg{ zaqgOOpPrr`9UYy2K<{TZ`Mo&VQT)@o7fXP{G2;CEyrk2BgOx%kab)y$8J7T^sS8hg zr?azj!d2Jpg(p8*E$soK0WizMG7QW#2bvzotYCcmZtCQ(DrJ%8_diQ^S%uK;(!^7JY?0gC z+?;t0&dSQ#ecN0~NDzGu!y&xci%CAKw8g~ItSkz#>i6b;6KPRC?=rUF zgg(Ao+p5A>8+rfr9R{NR2@+&x*FBu?Jdh%*&e4w?b_adGS{y(gN^PG1M1j`<`SA#~ ziFX)~(4h}AqWi$L3Ct2kqr*vv881D-S86$RymIs+a(5(PHs?hnqQX~YrW)c$#Ghde z8)b|p^!(26vss|85;Fq-%>)k^$^`@8kbv?C2B16@43tM=z>aBwFObhCmpoZdjyPhI z4+qEKTyQE`@N%Ax9X zwy#%QX*LV{yf^@vz`m-Lm~m|P6gZe9rQ`Kqi)KA0?X2VwntbmVXz{$0_$>cA74YA|@=pF>E zH@%$TcRKSs`mr<#sWnnfe0dY*^o;bxstBIxjiwPfb#`B-OBL#ZqA4HOd9e+%Bz6_K zU2a&(*lP55E9u8k)i_+(H`VY0^>+4+Ym$>KYOFCyd(6xWX(*vxotR(SG;pzpk^x8fLe7}>{G4N{fNSDfZy%l0)6w;lwNmF zMM3Zuf7{2_<7;&+VSf1u7>w9xe{Xr@cLbDScO0{HTToPBq3{!H1N*yx#_z6MH$*j~k;GNcr<>Mf+Qyex~9sYZ*FY8@qW9vy$V&hQ^)+S>#7ogY6^ zrxTNyC{Q*Nw);IQW6{d2Y(aa;L}MO$@e#3H2}ko5e~tHIeIBd(qS@dIr$Ju_%=iU2 z7T2v)DG+iyxAc&mPU)DMhCqF5N^$~YV>>r0sHSQRuEN)kz!=#5&_;u(a$9IA4UOdN zn-wz`R18n=3wDE>1Yfm@g1zYyvi^CO^LS<#xIZTvym63i71fEl+leX|w2!Aqoye^7 zCY&OU)oh~QB$nZk-H%N|SlI9+E>$y$P`_6xuF8?@2a=OWmP9=Bt)%8VC;*@}UX|x5 zBslw0of#^WU2{tFB z0FdS(Xu)q^UmhaEra__E1-f){a*D`$0^Ge8w?C`Qi%FxmZtZBXa;d_W_2JMJMh)%7 zoaBno?8h5ePB1~SOa$|pxpfaz)N$~-a_p}W3Q*l}z6LzY8tGZ+Gc#xI){~f=s6=a2 zTcP6W^G8*4ZW$&PcyxW8omEgJo>({i3#&AZdy6UW@2Y43ZwKshg3Uq|-YFRuh<+}% z-O4k2oN3B@KyrgmOS|2jez0)Z&l1ZHI@?e6;Eq0m@+C}T4pbnh3u;Xdr}Ol=*=!tW za9|47SV)^5w0NTuup7&iFBP2K-6f1>Nh&DstT zdLgm1Zu*E2xCi6M=aC4U?BO;F^#Q%&(QHwyav*FDdZhx<`R&6-=d98bQ)x>>YhR2> z+@ZS=r|b4jSqZ2Zl9FiYcY245glUG;6YQw|B(6G9Q63}|B#c`eBa1{