Fingerprint phishing lure pages and cluster campaigns by shared kit lineage.
Threat actors recycle DocuSign / Adobe / “secure document” / ScreenConnect HTML kits across domains. URLs burn; structure and marker sets persist. lure-lineage hashes a normalized HTML skeleton, tags known kit markers, and clusters captures so analysts can say “same kit family” without a full Maltego graph.
Built by Cipher Cortex · Research methodology from Intercept Cell.
git clone https://github.com/CipherCortex/lure-lineage.git
cd lure-lineage
pip install -e .
lure-lineage fingerprint fixtures/ --cluster
lure-lineage fingerprint fixtures/docusign_lure.html| ID | Signal |
|---|---|
docusign_chrome |
DocuSign branding / naming |
wufoo_form |
Wufoo form hosts |
adobe_share |
Adobe / Acrobat / Document Cloud |
microsoft_365 |
M365 / OneDrive / SharePoint |
google_drive |
Google account / Drive |
screenconnect_lure |
ScreenConnect / “View Document” |
it_support |
Helpdesk / remote support / secure document |
okta_style |
Okta sign-in patterns |
Structural hash ignores volatile href/src values so kit clones still cluster.
| Tool | Role |
|---|---|
| evidence-pack | Capture pages before fingerprinting |
| rmm-abuse-map | Follow MSI / relay links from lures |
| hijacked-infra-hunt | Find compromised hosts serving kits |
MIT © Cipher Cortex