Security Scan Report: phamtom.us

Redirected to: https://www.phamtom.us/

Submitted: Jan 20, 2026, 6:32:02 PMCompleted: Jan 20, 2026, 6:33:13 PMpubliccompleted
Loading additional data...

Summary

This website contacted 8 IPs in 2 countries across 8 domains to perform 111 HTTP transactions. The main domain is phamtom.us and was registered NaN years ago.

Submitted URL: http://phamtom.us/

Effective URL: https://www.phamtom.us/Redirected

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Phantom site impersonates Google on a brand‑new unranked domain; confirmed phishing scam.

Risk Factors
Brand impersonation/typosquatting of Google
Newly registered domain (<7 days)
Unranked domain with low reputation
Presence of forms on a brand‑impersonating page
Mismatch between displayed brand and final URL
Domain age information unavailable

Details

Page Title

Sign in - Google Accounts

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

documentation technical

(63%)

Domain Information

Domain 'phamtom.us' uses the United States country-code top-level domain (.us) with no subdomain. The core label 'phamtom' covers 7 characters holding two vowels versus five consonants. Splitting it apart reveals 2 words: pham, tom. Median word length comes out to 3.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://phamtom.us/

Page Load Overview

4.78s
Total Load Time
120
HTTP Requests
5
Domains
701 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:2,085 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical63% confidence
Type: spa
Method: ml+structural

All Detected Categories

documentation technical
63%
e-commerce shopping
56%
cryptocurrency blockchain
51%
technology software
51%
healthcare medical
51%

Detected Features

Search
Products
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1523.227.38.74Ottawa, Ontario, Canada
AS13335CLOUDFLARENET
1574.125.206.84United States
AS15169GOOGLE
15142.251.141.99United States
1523.227.38.67Ottawa, Ontario, Canada
AS13335CLOUDFLARENET
1534.120.87.25United StatesUnknown
15142.250.186.174United States
AS15169GOOGLE
15185.146.173.20United StatesUnknown
15142.250.185.68United StatesUnknown
1208--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1AB35A6CB9231B07FFD73A4F5E584E949F2884DC1E91A4A76BC71A61342EBAE61351330

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:xCMq3j6/8+sq3j6/8+Kq3j6/8+tq3j6/8+Iq3j6/8+DSrpeQISNt1/SMoiqo6/8m:xCtSrpSMoxjTPusKky6Vh7s3g00wnKRp

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:1111034:JGLhFMpGalCZEKKQRMYAR0Iq0AFCFqS4xPCgLLhAQwYJiJXBZJBkAAhCoDNkxFDZSIBIK2D4jUmE0h2EB9QBMgEECInFAYyC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffe7e7e7e3efff
Perceptual Hash:e69b896499336699
Difference Hash:00000c0c0c051400
Wavelet Hash:3c2424242727273f
Color Hash:#c2d22d

Other Hashes

Crop Resistant:00000c0c0c051400

Scan History

Scan history not available

Unable to load historical scan data