kgretzky / evilginx2

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
BSD 3-Clause "New" or "Revised" License
10.23k stars 1.87k forks source link

Evilginx handshake problem #993

Open ghost opened 6 months ago

ghost commented 6 months ago

[09:38:57] [war] session cookie not found: https://www.tech-a-solutions.website/ajax/webstorage/process_keys/?state=1 (223.29.224.225) [facebook] [09:42:22] [war] session cookie not found: https://m.tech-a-solutions.website/ (195.211.77.140) [facebook] [09:42:22] [war] [facebook] unauthorized request: https://m.tech-a-solutions.website/ (Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36) [195.211.77.140] [09:43:08] [war] session cookie not found: https://www.tech-a-solutions.website/ajax/webstorage/process_keys/?state=1 (223.29.224.225) [facebook] [09:45:43] [war] session cookie not found: https://m.tech-a-solutions.website/ (195.211.77.142) [facebook] [09:45:43] [war] [facebook] unauthorized request: https://m.tech-a-solutions.website/ (Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36) [195.211.77.142] [09:48:38] [war] session cookie not found: https://www.tech-a-solutions.website/ajax/bz?__a=1&__aaid=0&__ccg=EXCELLENT&__dyn=7xe6E5aQ1PyUbFp61swgE98nwgU29zEdEc8uwdK0lW4o3Bw5VCwjE3awbG78b87C0yE7i0n24o5-0me2218w5uw5Uwdq0Ho2eU5O0PU1AE17U2ZwrU19E36w&__hs=19702.BP%3ADEFAULT.2.0..0.0&__hsi=7311268927365911247&__req=6&__rev=1010328797&__s=f7i6n8%3Aqajges%3A2z794u&__spin_b=trunk&__spin_r=1010328797&__spin_t=1702287450&__user=0&dpr=1.5&jazoest=2973&lsd=AVpdPNeX4pc (223.29.224.225) [facebook] [09:48:38] [war] [facebook] unauthorized request: https://www.tech-a-solutions.website/ajax/bz?__a=1&__aaid=0&__ccg=EXCELLENT&__dyn=7xe6E5aQ1PyUbFp61swgE98nwgU29zEdEc8uwdK0lW4o3Bw5VCwjE3awbG78b87C0yE7i0n24o5-0me2218w5uw5Uwdq0Ho2eU5O0PU1AE17U2ZwrU19E36w&__hs=19702.BP%3ADEFAULT.2.0..0.0&__hsi=7311268927365911247&__req=6&__rev=1010328797&__s=f7i6n8%3Aqajges%3A2z794u&__spin_b=trunk&__spin_r=1010328797&__spin_t=1702287450&__user=0&dpr=1.5&jazoest=2973&lsd=AVpdPNeX4pc (Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36) [223.29.224.225] [09:51:59] [war] session cookie not found: https://www.tech-a-solutions.website/ajax/bz?__a=1&__aaid=0&__ccg=EXCELLENT&__dyn=7xe6E5aQ1PyUbFp61swgE98nwgU29zEdEc8uwdK0lW4o3Bw5VCwjE3awbG78b87C0yE7i0n24o5-0me2218w5uw5Uwdq0Ho2eU5O0PU1AE17U2ZwrU19E36w&__hs=19702.BP%3ADEFAULT.2.0..0.0&__hsi=7311268927365911247&__req=7&__rev=1010328797&__s=%3Aqajges%3A2z794u&__spin_b=trunk&__spin_r=1010328797&__spin_t=1702287450&__user=0&dpr=1.5&jazoest=2973&lsd=AVpdPNeX4pc (223.29.224.225) [facebook] [09:51:59] [war] [facebook] unauthorized request: https://www.tech-a-solutions.website/ajax/bz?__a=1&__aaid=0&__ccg=EXCELLENT&__dyn=7xe6E5aQ1PyUbFp61swgE98nwgU29zEdEc8uwdK0lW4o3Bw5VCwjE3awbG78b87C0yE7i0n24o5-0me2218w5uw5Uwdq0Ho2eU5O0PU1AE17U2ZwrU19E36w&__hs=19702.BP%3ADEFAULT.2.0..0.0&__hsi=7311268927365911247&__req=7&__rev=1010328797&__s=%3Aqajges%3A2z794u&__spin_b=trunk&__spin_r=1010328797&__spin_t=1702287450&__user=0&dpr=1.5&jazoest=2973&lsd=AVpdPNeX4pc (Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36) [223.29.224.225] [09:52:02] [war] session cookie not found: https://www.tech-a-solutions.website/ajax/bz?__a=1&__aaid=0&__ccg=EXCELLENT&__dyn=7xe6E5aQ1PyUbFp61swgE98nwgU29zEdEc8uwdK0lW4o3Bw5VCwjE3awbG78b87C0yE7i0n24o5-0me2218w5uw5Uwdq0Ho2eU5O0PU1AE17U2ZwrU19E36w&__hs=19702.BP%3ADEFAULT.2.0..0.0&__hsi=7311268927365911247&__req=8&__rev=1010328797&__s=rk7krv%3Aqajges%3A2z794u&__spin_b=trunk&__spin_r=1010328797&__spin_t=1702287450&__user=0&dpr=1.5&jazoest=2973&lsd=AVpdPNeX4pc (223.29.224.225) [facebook] [09:52:02] [war] [facebook] unauthorized request: https://www.tech-a-solutions.website/ajax/bz?__a=1&__aaid=0&__ccg=EXCELLENT&__dyn=7xe6E5aQ1PyUbFp61swgE98nwgU29zEdEc8uwdK0lW4o3Bw5VCwjE3awbG78b87C0yE7i0n24o5-0me2218w5uw5Uwdq0Ho2eU5O0PU1AE17U2ZwrU19E36w&__hs=19702.BP%3ADEFAULT.2.0..0.0&__hsi=7311268927365911247&__req=8&__rev=1010328797&__s=rk7krv%3Aqajges%3A2z794u&__spin_b=trunk&__spin_r=1010328797&__spin_t=1702287450&__user=0&dpr=1.5&jazoest=2973&lsd=AVpdPNeX4pc (Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36) [223.29.224.225] [09:52:16] [war] session cookie not found: https://www.tech-a-solutions.website/mail (223.29.224.225) [facebook] [09:52:16] [imp] [1] [facebook] new visitor has arrived: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 (223.29.224.225) [09:52:16] [inf] [1] [facebook] landing URL: https://www.tech-a-solutions.website/mail [09:52:19] [war] session cookie not found: https://www.tech-a-solutions.website/data/manifest/ (223.29.224.225) [facebook] [09:52:20] [war] session cookie not found: https://www.tech-a-solutions.website/ajax/bz?__a=1&__aaid=0&__ccg=UNKNOWN&__dyn=7xe6E5aQ1PyUbFp61swgE98nwgU29zEdEc8uwdK0lW4o3Bw5VCwjE3awbG78b87C0yE7i0n24o5-0me2218w5uw5Uwdq0Ho2eU5O0PU1mUdEG0hi0Lo6-0iq0NE&__hs=19702.BP%3ADEFAULT.2.0..0.0&__hsi=7311272736423306389&__req=1&__rev=1010328797&__s=rk7krv%3As8nk5r%3Aw4z5k3&__spin_b=trunk&__spin_r=1010328797&__spin_t=1702288337&__user=0&dpr=1.5&jazoest=2909&lsd=AVos01Fr9So (223.29.224.225) [facebook] [09:52:26] [war] session cookie not found: https://www.tech-a-solutions.website/login/device-based/regular/login/?login_attempt=1&lwv=100 (223.29.224.225) [facebook] [09:52:26] [war] session cookie not found: https://www.tech-a-solutions.website/login/device-based/regular/login/ (223.29.224.225) [facebook] [09:52:27] [war] session cookie not found: https://www.tech-a-solutions.website/ajax/bz?__a=1&__aaid=0&__ccg=UNKNOWN&__dyn=7xe6E5aQ1PyUbFp61swgE98nwgU29zEdEc8uwdK0lW4o3Bw5VCwjE3awbG78b87C0yE7i0n24o5-0me2218w5uw5Uwdq0Ho2eU5O0PU1mUdEG0hi0Lo6-0iq0NE&__hs=19702.BP%3ADEFAULT.2.0..0.0&__hsi=7311272736423306389&__req=2&__rev=1010328797&__s=rk7krv%3As8nk5r%3Aw4z5k3&__spin_b=trunk&__spin_r=1010328797&__spin_t=1702288337&__user=0&dpr=1.5&jazoest=2909&lsd=AVos01Fr9So (223.29.224.225) [facebook] [09:52:27] [war] session cookie not found: https://www.tech-a-solutions.website/ajax/bz?__a=1&__aaid=0&__ccg=UNKNOWN&__dyn=7xe6E5aQ1PyUbFp61swgE98nwgU29zEdEc8uwdK0lW4o3Bw5VCwjE3awbG78b87C0yE7i0n24o5-0me2218w5uw5Uwdq0Ho2eU5O0PU1mUdEG0hi0Lo6-0iq0NE&__hs=19702.BP%3ADEFAULT.2.0..0.0&__hsi=7311272736423306389&__req=4&__rev=1010328797&__s=rk7krv%3As8nk5r%3Aw4z5k3&__spin_b=trunk&__spin_r=1010328797&__spin_t=1702288337&__user=0&dpr=1.5&jazoest=2909&lsd=AVos01Fr9So (223.29.224.225) [facebook] [09:52:28] [war] session cookie not found: https://www.tech-a-solutions.website/data/manifest/ (223.29.224.225) [facebook] [09:52:29] [war] session cookie not found: https://www.tech-a-solutions.website/ajax/bz?__a=1&__aaid=0&__ccg=UNKNOWN&__dyn=7xe6E5aQ1PyUbFp61swgE98nwgU29zEdEc8uwdK0lW4o3Bw5VCwjE3awbG78b87C0yE7i0n24o5-0me2218w5uw5Uwdq0Ho2eU5O0PU1AE17U2ZwrU19E36w&__hs=19702.BP%3ADEFAULT.2.0..0.0&__hsi=7311272774897220034&__req=1&__rev=1010328797&__s=rk7krv%3As8nk5r%3Asibyoz&__spin_b=trunk&__spin_r=1010328797&__spin_t=1702288346&__user=0&dpr=1.5&jazoest=21018&lsd=AVpgh7tIRks (223.29.224.225) [facebook] [09:52:33] [war] session cookie not found: https://www.tech-a-solutions.website/ajax/bz?__a=1&__aaid=0&__ccg=UNKNOWN&__dyn=7xe6E5aQ1PyUbFp61swgE98nwgU29zEdEc8uwdK0lW4o3Bw5VCwjE3awbG78b87C0yE7i0n24o5-0me2218w5uw5Uwdq0Ho2eU5O0PU1AE17U2ZwrU19E36w&__hs=19702.BP%3ADEFAULT.2.0..0.0&__hsi=7311272774897220034&__req=2&__rev=1010328797&__s=rk7krv%3As8nk5r%3Asibyoz&__spin_b=trunk&__spin_r=1010328797&__spin_t=1702288346&__user=0&dpr=1.5&jazoest=21018&lsd=AVpgh7tIRks (223.29.224.225) [facebook] [09:52:33] [war] session cookie not found: https://www.tech-a-solutions.website/ajax/bz?__a=1&__aaid=0&__ccg=UNKNOWN&__dyn=7xe6E5aQ1PyUbFp61swgE98nwgU29zEdEc8uwdK0lW4o3Bw5VCwjE3awbG78b87C0yE7i0n24o5-0me2218w5uw5Uwdq0Ho2eU5O0PU1AE17U2ZwrU19E36w&__hs=19702.BP%3ADEFAULT.2.0..0.0&__hsi=7311272774897220034&__req=3&__rev=1010328797&__s=rk7krv%3As8nk5r%3Asibyoz&__spin_b=trunk&__spin_r=1010328797&__spin_t=1702288346&__user=0&dpr=1.5&jazoest=21018&lsd=AVpgh7tIRks (223.29.224.225) [facebook]