CO
Identical webpage content hash shared across 36 domains indicates a cloned codebase or template used to rapidly deploy multiple scam sites with the same underlying HTML/CSS/JavaScript structure. This forensic signal suggests coordinated infrastructure where a single site design was replicated across numerous domains, a common tactic in phishing and cryptocurrency fraud campaigns to maximize reach while minimizing development effort.
Fingerprint
ecb2ada647a2efb41fdc9748be4fba23e264c68220399a4cd0409f29c5680a05- Detections
- 36
- Hash type
- Content hash
- Status
- Active
- Last scanned
- May 2026
12026-03
272026-04
82026-05
Detected domains
36aiaiis.com
OnlineTrust 10Apr 25, 2026astraxexchange.com
OnlineTrust 1Apr 25, 2026beuce.com
OnlineTrust 1Apr 25, 2026biscoins.com
OnlineTrust 10Apr 29, 2026bitop.com
OnlineTrust 19Apr 25, 2026btcschg.com
OnlineTrust 1May 1, 2026convergentwealthadvisors.com
OnlineTrust 19Apr 25, 2026crypen.com
OnlineTrust 25Apr 25, 2026ctante.com
OnlineTrust 1May 1, 2026darkcherries.com
OnlineTrust 10Apr 25, 2026