DOM
Identical DOM structure hash detected across 40 scam domains indicates these sites share a cloned HTML framework and layout architecture, suggesting they were generated from a common template or automated creation tool. This forensic signal demonstrates coordinated infrastructure deployment characteristic of organized phishing or fraudulent scheme networks.
Fingerprint
2911cf8b9a6d0d41046493a36bfe83ba3889d67236f02454722cd83b300ce392- Detections
- 40
- Hash type
- DOM structure
- Status
- Active
- Last scanned
- May 2026
402026-03
Detected domains
40betkai.win
OnlineTrust 1Mar 22, 2026betmiqx.com
OnlineTrust 1Mar 23, 2026buorex.com
OnlineTrust 1Mar 23, 2026casewin.to
OnlineTrust 1Mar 21, 2026darodex.com
OnlineTrust 1Mar 20, 2026ewgamb.cc
OnlineTrust 1Mar 23, 2026ferospin.com
OnlineTrust 1Mar 25, 2026galowex.com
OnlineTrust 1Mar 23, 2026garopex.com
OnlineTrust 1Mar 20, 2026kovadex.com
OnlineTrust 1Mar 20, 2026
Related signals
10BU
Build #26
Nexus Syndicate
Active
- 118
- detections
FA
Favicon #42
Nexus Syndicate
Active
- 81
- detections
DOM
DOM #30
Nexus Syndicate
Active
- 77
- detections
BU
Build #18
Nexus Syndicate
Active
- 73
- detections
BU
Build #7
Nexus Syndicate
Active
- 72
- detections
FA
Favicon #50
Nexus Syndicate
Active
- 55
- detections
DOM
DOM #47
Nexus Syndicate
Active
- 53
- detections
FA
Favicon #41
Nexus Syndicate
Active
- 23
- detections
FA
Favicon #11
Nexus Syndicate
Active
- 17
- detections
BU
Build #55
Nexus Syndicate
Active
- 16
- detections