DEV Community

relayshieldadmin
relayshieldadmin

Posted on Originally published at blog.relayshield.net

Scam-Kit Fingerprinting API: Turn Any Phishing Link Into a Matchable Kit Identity

Every phishing wave reuses the same kits. Tycoon 2FA, Evilginx, Sneaky 2FA, Darcula: built once, deployed thousands of times. Only per-victim nonces and rotated credentials change between sightings.

RelayShield's scam-kit fingerprinting API turns one suspicious link into a stable kit identity: a deterministic kit_<sha256> fingerprint ID, identical for the same kit across sightings.

What the fingerprint captures

POST /v1/payg/scamkit-fingerprint
Enter fullscreen mode Exit fullscreen mode

Records what the kit's server actually does:

  • Up to 5 redirect hops recorded
  • Response headers, including kit tells like X-Evilginx
  • TLS facts for the kit host: version, cipher, issuer, SANs, certificate age
  • Up to 2 bounded secondary fetches, each hashed and recorded

Honesty rule: we never compute JA3/JA4 locally. Those fingerprint the TLS client (our fetcher), not the kit server.

Secrets and tokens are stripped before hashing, so kits differing only in rotated credentials fingerprint identically. Families resolve against 20 approved names; anything else stays suggested until a human approves it. No-hit always says "no flags found", never "safe".

Pricing

$0.50  fingerprint  (/v1/payg/scamkit-fingerprint)
$0.10  match        (/v1/payg/scamkit-match)
$5.50  campaign scan, up to 25 indicators
Enter fullscreen mode Exit fullscreen mode

Backed by the same corpus: 123 monitored Telegram marketplaces, 661K+ indicators, 8.4M+ citations.

Full post: https://blog.relayshield.net/scam-kit-fingerprinting-api

Top comments (0)