Security Scan Report: roninchain.co.com

Redirected to: https://roninchain.co.com/

Submitted: Nov 22, 2025, 8:29:31 AMCompleted: Nov 22, 2025, 8:30:35 AMpubliccompleted
Loading additional data...

Summary

This website contacted 11 IPs in 3 countries across 4 domains to perform 10 HTTP transactions. The main domain is roninchain.co.com.

Submitted URL: http://roninchain.co.com/

Effective URL: https://roninchain.co.com/Redirected

AI Security Verdict

High Risk

Confidence: 88%

8
Risk Score

Impersonates Ronin Wallet on an unranked, likely new domain – high risk phishing.

Risk Factors
Brand impersonation of Ronin Wallet on a non‑official domain
Unranked domain with low reputation
Likely newly registered domain (<90 days) mimicking a known brand
Domain age information unavailable

Details

Page Title

Ronin Wallet Download - Secure Gaming Wallet for Axie Infinity & Web3 Games

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

cryptocurrency blockchain

(96%)

Domain Information

You're looking at domain 'roninchain.co.com' on the commercial generic top-level domain (.com), featuring subdomain 'roninchain'. The registrable portion 'co' spans 2 characters holding one vowel versus one consonant. Breaking it apart gives one word: co. Average segment length settles at 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://roninchain.co.com/

Page Load Overview

0.84s
Total Load Time
10
HTTP Requests
4
Domains
203 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:6,215 chars
Detector Agreement:100%

Website Classification

Primary Category

cryptocurrency blockchain96% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

cryptocurrency blockchain
96%
technology software
81%
entertainment media
76%
finance banking
76%
download file sharing
56%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4172.217.23.99United States
AS15169GOOGLE
2185.185.71.63Russia
AS35278Sprinthost.ru LLC
1142.250.186.42United States
AS15169GOOGLE
1104.26.3.143United States
AS13335CLOUDFLARENET
0172.67.68.11United States
AS13335CLOUDFLARENET
0104.26.2.143United States
AS13335CLOUDFLARENET
02606:4700:20::681a:28fUnited States
AS13335CLOUDFLARENET
02a00:1450:4001:831::2003Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
02a00:1450:4001:81c::200aFrankfurt am Main, Hesse, Germany
AS15169GOOGLE
02606:4700:20::ac43:440bUnited States
AS13335CLOUDFLARENET
1011--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B853A426B1F00877199391F1B6A27B6DBA19D083CD6BCCA9B69D02156FC7CA64CD334C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:vkchnTp+WbQU05QM5ZCD+RpKPcjqJGFmouA3A0S1KkNT:LheD/J9kl

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:63798:QmDKgBEoEhJCBgKWKSTEEClIRQDjVIcEfyhiAqQAoSQQRwJ5EQINKFUBExfuAIgJ4uIaIqgfRIRCtAExcTQggAwEKDpImDEQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:N/A
Perceptual Hash:N/A
Difference Hash:N/A
Wavelet Hash:N/A
Color Hash:N/A

Other Hashes

Crop Resistant:N/A

Scan History

Scan history not available

Unable to load historical scan data