Security Scan Report: phantomw.net

Redirected to: https://phantomw.net/

Site favicon
Submitted: Oct 27, 2025, 9:50:43 PMCompleted: Oct 27, 2025, 9:52:22 PMpubliccompleted
Loading additional data...

Summary

This website contacted 1 IP in 1 country across 1 domain to perform 5 HTTP transactions. The main domain is phantomw.net.

Submitted URL: http://phantomw.net/

Effective URL: https://phantomw.net/Redirected

AI Security Verdict

High Risk

Confidence: 85%

7
Risk Score

Site impersonates the Phantom wallet on a low‑reputation domain with suspicious redirects; treat as high‑risk phishing.

Risk Factors
Brand impersonation of a well‑known crypto wallet on an unranked domain
Circular redirect detected
Unranked/low‑reputation domain
Domain age unknown (likely newly registered)
Domain age information unavailable

Details

Page Title

Phantom — Crypto & NFT Wallet — Solana | Download Extension | Login

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

other

(65%)

Domain Information

The domain 'phantomw.net' uses the network infrastructure generic top-level domain (.net) with no subdomain. The second-level label 'phantomw' is 8 characters long split between 2 vowels and six consonants. Word splitting yields 2 words: phantom, w. Average segment length settles at four characters. Most frequently, 'w' shows up in Polish. Secondary signals appear in Chinese (Zhuyin) and English.

Screenshot

Security scan screenshot of http://phantomw.net/

Page Load Overview

21.28s
Total Load Time
5
HTTP Requests
1
Domains
0 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:4,287 chars
Detector Agreement:100%

Website Classification

Primary Category

other65% confidence
Type: static
Method: ml+structural

All Detected Categories

other
65%
e-commerce
52%
cryptocurrency
22%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
594.241.143.45Greece
AS9123Jsc timeweb
51--

Detected Technologies2

JQueryv3.6.1
100%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T136F2E8513740A03EC0232BDAA1A2DB5F646BB1CFC7450658FDBD6692EFC0DD58436AE8

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:0u11bw1Znn1yj1u1i818+/xZ9YrJwZUP1M18N1vMrV1R1W31yOY1jENPEbctMv2s:0wbYUhiUfEriTNPtYEsn7Z5

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:36352:cgcgFQEJRgAhhSFooLoYxBAgAoTAAoODwiv6DICQIBiBBERBHIDgfcgAYEAUCUAcKmATCVJ6IWQKYCoDNowEQghX0GB0JJwh

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3fffffffffffffff
Perceptual Hash:8707070f0f0f1f1f
Difference Hash:c000000000000000
Wavelet Hash:30f0f0f0f0f0f0f0
Color Hash:#d28279

Other Hashes

Crop Resistant:c000000000000000

Scan History

Scan history not available

Unable to load historical scan data