One URL.
The whole network.
Drop a domain. Get the cluster, the certificate, the wallet, and a 14-chain forensic score .
Headless SPA rendering
Anti-bot bypass
Zero identity logging
TLS Layer
protocol TLSv1.3
issuer LE · 3d age
Antivirus
Bitdefender malware
Kaspersky phishing
Cluster
17 nodes · 24 edges
11 mirror domains
IOC Layer
0x9a3c…b7e2 → mixer
@support_ops88
Watchdogs
AMF co-listed
FCA warning
Network
200 GET /
401 /api/airdrop
Trust Score
04/ 100
6 chains · 11 cluster hits
Validated against
Five layers, one verdict.
Identity & Cryptography
TLS handshake, X.509, multi-registry WHOIS.
Content & Build Fingerprint
DOM hashes, JS topology, favicon SHA-256.
Network Telemetry
Full HTTP log, redirect chain, load timing.
IOC Extraction
Wallets, handles, emails, addresses.
1
Acquire
Headless SPA fetch
2
Extract
Forensic signals
3
Validate
Cross-engine + watchdog
4
Persist
Neo4j graph commit
5
Score
14 deterministic chains
One signal.
A whole scam farm.
First-party Neo4j graph . Real cluster, real edges, real time.
CodeDOM, favicon, JS path
InfrastructureIP, ASN, TLS
Identityhandles, emails
Financialwallets, txs
cluster · #fbz-04
17 nodes · 24 edges Deterministic, never an opinion.
14 penalty chains. 2 bonus chains. See the algorithm →
sample · fake-binance-pro.io
04/ 100
High Risk
Hover the distribution to inspect zones
0–2425–4445–6970–8485–100
Multiple penalty chains tripped. Strong regulator co-listing or blocklist hits.
Direct ingest. No middleman.
AV engines, financial watchdogs , community Web3 blocklists.
Security engines
Cross-engine validation
VirusTotalrequest-time
Google Safe Browsinglive
Cloudflare Radar Intellive
MetaMask Eth-PhishList6h refresh
ScamSniffer6h refresh
Phishing.Database6h refresh
Crypto Scam Intel6h refresh