Security Scan Report: phantom-backup.com

Redirected to: https://phantom-backup.com/webr/one.html

Submitted: Dec 5, 2025, 3:35:51 AMCompleted: Dec 5, 2025, 3:37:22 AMpubliccompleted
Loading additional data...

Summary

This website contacted 1 IP in 1 country across 1 domain to perform 4 HTTP transactions. The main domain is phantom-backup.com and was registered NaN years ago.

Submitted URL: https://phantom-backup.com/webr/

Effective URL: https://phantom-backup.com/webr/one.htmlRedirected

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

High‑risk phishing site impersonating the Phantom wallet

Risk Factors
Brand impersonation of Phantom wallet on a newly registered, unranked domain
Recent domain age (<180 days) increasing suspicion
Lack of any legitimate contact or corporate information
Domain age information unavailable

Details

Page Title

Phantom Wallet

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

other

(48%)

Domain Information

The domain name 'phantom-backup.com' uses the commercial generic top-level domain (.com) and has no subdomain. The registrable portion 'phantom-backup' spans 14 characters with four vowels and 9 consonants, plus one hyphen. Tokenizing the label suggests 2 words: phantom, backup. Expect 6.5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://phantom-backup.com/webr/

Page Load Overview

1.61s
Total Load Time
4
HTTP Requests
1
Domains
1.4 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:128 chars
Detector Agreement:100%

Website Classification

Primary Category

other48% confidence
Type: static
Method: ml+structural

All Detected Categories

other
48%
malicious
25%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4172.86.113.197Dallas, Texas, United States
AS14956ROUTERHOSTING
41--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T16D51724EA3D7160AA513B5601FFBA6063666D40BC149CA283FCC1AD0DF8A6D99C637CC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:nhSUGTtQ7ipRQNc1R/RVJZa83NPfFae63xWgPMF2/W9E6v4yqknJSjra+aR:nhbYQIJZlPtaeA0g0Fa9+zVJS3aR

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:2936:gQQAAJCIAVAwQAARCIAAACAAEAQBACABgAUAAAgCgJCAAAAAABEAABAAAAAAAIAAcDAgERABhAIdAAIAEQAAAAAABhgAJQRE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffe7c3e7e7ffff
Perceptual Hash:e666999926666699
Difference Hash:0c324d4d4d4d320c
Wavelet Hash:0f0f0303c3c3cfcf
Color Hash:#98e06c

Scan History

Scan history not available

Unable to load historical scan data