Skip to content

About

Fingerprint phishing lure pages and cluster campaigns by shared kit lineage

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

1 Commit

Folders and files

Repository files navigation

Lure Lineage

License: MIT Python 3.10+

Fingerprint phishing lure pages and cluster campaigns by shared kit lineage.

Threat actors recycle DocuSign / Adobe / “secure document” / ScreenConnect HTML kits across domains. URLs burn; structure and marker sets persist. lure-lineage hashes a normalized HTML skeleton, tags known kit markers, and clusters captures so analysts can say “same kit family” without a full Maltego graph.

Built by Cipher Cortex · Research methodology from Intercept Cell.


Quick start

git clone https://github.com/CipherCortex/lure-lineage.git
cd lure-lineage
pip install -e .

lure-lineage fingerprint fixtures/ --cluster
lure-lineage fingerprint fixtures/docusign_lure.html

Markers (v0.1)

ID Signal
docusign_chrome DocuSign branding / naming
wufoo_form Wufoo form hosts
adobe_share Adobe / Acrobat / Document Cloud
microsoft_365 M365 / OneDrive / SharePoint
google_drive Google account / Drive
screenconnect_lure ScreenConnect / “View Document”
it_support Helpdesk / remote support / secure document
okta_style Okta sign-in patterns

Structural hash ignores volatile href/src values so kit clones still cluster.

Related tools

Tool Role
evidence-pack Capture pages before fingerprinting
rmm-abuse-map Follow MSI / relay links from lures
hijacked-infra-hunt Find compromised hosts serving kits

License

MIT © Cipher Cortex

About

Fingerprint phishing lure pages and cluster campaigns by shared kit lineage

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages