You are on page 1of 15

=Advanced

Phishin

I
1mea
!#
Methods
~

OXshU
*

1.",ou
How Alengine efect
it
similar domain Logo matching
->


Name
(URL Analysis)
9

·oth
1
content
Analysis I
!
* -

Reputational
Analysis Behavioural
Analysis @ Oxishu
THEM
Let's think

# Ryp
@ Oxishu
Let's thinkTHEM

zz
#
#
&

Ryp, zz
#

Investment &&
↓ Profit ↑ @ Oxishu

FR
#* -

L
renonteclinical
·
Less
read
Various Freemium services
·
B Technical
&
investment

Use their technical


· firebase hosting skill to find out ways
· cloudflare pages
· preview domain to evade detection
a
Easy tool
-I
· to use

@ Oxishu
=Advanced
Phishing Techniques
↑11/ -
=***
1.
=
@ Oxishu
* Classification
... &
=>

15
&
* THREAT
-

SER

In our ..

***
NT
-

* Crawler
@ Oxishu
toting
# in.. crawling
⑦ forbidden
1

&.
=> rf
by · a
15
&

SBENo-o

⑭ ur ...
*

0xx
- NT

# in
xyz.

@ Oxishu
yp unique link
⑧ using Redirector
⑦. ② set cookies ↑
·
to
-↑
*xZICOM/xZD%·go|
Redirect*
ed
->
G


&
*
↑if try from
to
access
anotherbrowser

Diffrent- ·
Browser

@ Oxishu
③ Blockers VPN

#impo
#MP

securityendor
=

Gyo location

Cloud
Servic

@ Oxishu
User
④ Requiring a login
⑭---higm
*(8
( < ==

9.e.
with google
↓" in
If logged in
If not logged in with
google

#fil
1
* =
*

Google

@ Oxishu
Legitimate url ⑮ Open Redirects
*

*Ay.Com3urL=x


+

phishing
=

url
#oz
*
1 -
=
>

F
7 -
SMS OR
EMAIL

# Ryp
@ Oxishu
⑥ 2FABypass

#.
gets the cookie

,verity
th
Login
with
#ElleEvilgnixz
2FA =
③ Set Cookie
-

@ Oxishu

Malform URLs

⑭11
-xyz.online

Y
Ms Nxyz.online/

#UR,YYER
1
↑ps:1l
xyz.online

@ Oxishu
Think
beforeyou click
anythin

...

Foul
1#
* =

You might also like