Dev.to Security ๐Ÿ” Cybersecurity ๐Ÿ‘ 0

Scam-Kit Fingerprinting API: Turn Any Phishing Link Into a Matchable Kit Identity

Every phishing wave reuses the same kits. Tycoon 2FA, Evilginx, Sneaky 2FA, Darcula: built once, deployed thousands of times. Only per-victim nonces and rotated credentials change between sightings. RelayShield's scam-k

Every phishing wave reuses the same kits. Tycoon 2FA, Evilginx, Sneaky 2FA, Darcula: built once, deployed thousands of times. Only per-victim nonces and rotated credentials change between sightings.

RelayShield's scam-kit fingerprinting API turns one suspicious link into a stable kit identity: a deterministic kit_<sha256> fingerprint ID, identical for the same kit across sightings.

What the fingerprint captures

POST /v1/payg/scamkit-fingerprint

Records what the kit's server actually does:

  • Up to 5 redirect hops recorded
  • Response headers, including kit tells like X-Evilginx
  • TLS facts for the kit host: version, cipher, issuer, SANs, certificate age
  • Up to 2 bounded secondary fetches, each hashed and recorded

Honesty rule: we never compute JA3/JA4 locally. Those fingerprint the TLS client (our fetcher), not the kit server.

Secrets and tokens are stripped before hashing, so kits differing only in rotated credentials fingerprint identically. Families resolve against 20 approved names; anything else stays suggested until a human approves it. No-hit always says "no flags found", never "safe".

Pricing

$0.50  fingerprint  (/v1/payg/scamkit-fingerprint)
$0.10  match        (/v1/payg/scamkit-match)
$5.50  campaign scan, up to 25 indicators

Backed by the same corpus: 123 monitored Telegram marketplaces, 661K+ indicators, 8.4M+ citations.

Full post: https://blog.relayshield.net/scam-kit-fingerprinting-api

๐Ÿ“ฐ Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes โ€” full credit and traffic to the original publisher.