Scam-Kit Fingerprinting API: Turn Any Phishing Link Into a Matchable Kit Identity
Every phishing wave reuses the same kits. Tycoon 2FA, Evilginx, Sneaky 2FA, Darcula: built once, deployed thousands of times. Only per-victim nonces and rotated credentials change between sightings. RelayShield's scam-k
Every phishing wave reuses the same kits. Tycoon 2FA, Evilginx, Sneaky 2FA, Darcula: built once, deployed thousands of times. Only per-victim nonces and rotated credentials change between sightings.
RelayShield's scam-kit fingerprinting API turns one suspicious link into a stable kit identity: a deterministic kit_<sha256> fingerprint ID, identical for the same kit across sightings.
What the fingerprint captures
POST /v1/payg/scamkit-fingerprint
Records what the kit's server actually does:
- Up to 5 redirect hops recorded
- Response headers, including kit tells like
X-Evilginx - TLS facts for the kit host: version, cipher, issuer, SANs, certificate age
- Up to 2 bounded secondary fetches, each hashed and recorded
Honesty rule: we never compute JA3/JA4 locally. Those fingerprint the TLS client (our fetcher), not the kit server.
Secrets and tokens are stripped before hashing, so kits differing only in rotated credentials fingerprint identically. Families resolve against 20 approved names; anything else stays suggested until a human approves it. No-hit always says "no flags found", never "safe".
Pricing
$0.50 fingerprint (/v1/payg/scamkit-fingerprint)
$0.10 match (/v1/payg/scamkit-match)
$5.50 campaign scan, up to 25 indicators
Backed by the same corpus: 123 monitored Telegram marketplaces, 661K+ indicators, 8.4M+ citations.
Full post: https://blog.relayshield.net/scam-kit-fingerprinting-api
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes โ full credit and traffic to the original publisher.