• We just launched and are currently in beta. Join us as we build and grow the community.

How to Hide Phishing Link Behind Real Domain

shelleyK

Dynamic Debugger
S Rep
0
0
0
Rep
0
S Vouches
0
0
0
Vouches
0
Posts
168
Likes
11
Bits
2 MONTHS
2 2 MONTHS OF SERVICE
LEVEL 1 400 XP
White-Black-and-Red-Modern-Networking-Marketing-Presentation-2.png


Hey Folks, in this tutorial we’re gonna use a tool that can convert a phishing link to a normal web link like Google or YouTube called “maskphish“. MaskPhish is a small and simple tool written in the bash language, which is used to hide phishing URLs under normal looking URLs (google.com or facebook.com).

Let’s take a look 🙂 !!

Installation

Similar at all the time now this time also we will download it first using the following command.This is a very small tool that does not require any additional dependencies, so we can use it in any android third party app. After downloading is done then we will go to the directory of this tool. That’s it we can boot this tool using the bash command.

git clone https://github.com/jaykali/maskphish
cd maskphish
./maskphish123git clone
https://github.com/jaykali/maskphishcd maskphish./maskphish

1-24.png


Done 🙂 !! Now here we have to enter the phishing URL that we want to modify.

2-23.png


We take help of advphishing tool to create an fake e-commerce website phishing page. You can see the full article on it from here.

3-24.png


After entering the phishing URL it tells us to enter the name of any domain behind which we want to hide. Finally after entering some social engineering words it successfully changes the phishing UR that you can see the image below.

5-19.png


Nice 🙂 !! The URL looks like the actual one, but the phishing page will open as soon as the victim clicks the link, as you can see.

6-21.png


Great 🙂 !! As soon as the victims enter their credentials on the phishing page, they will go to the attacker without their knowledge.

7-17.png


Also there is no better way to hide your phishing URLs behind well-known domains.

About the AuthorShubham Goyal Certified Ethical Hacker, information security analyst, penetration tester and researcher. Can be Contact on Linkedin.
 

435,057

313,705

313,714

Top