Security Scan Report: phantom-mobile-test.pages.dev

Site favicon
Submitted: Sep 30, 2026, 12:45:06 PMCompleted: Sep 30, 2026, 12:45:52 PMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 55%

5
Risk Score

Security-research test harness on a free pages.dev subdomain that builds Solana wallet-drainer payloads and asks users to connect a wallet. No forms, no Indicators of Compromise, no malware; it self-labels as a test and says not to approve, but the live drainer payloads warrant caution.

Risk Factors (3)
Wallet-drainer-class signing payloads are live on the page and could harm a user who connects a real wallet and approves
Subdomain name and branding invoke Phantom (a third-party wallet) on a domain that is not Phantom's official site
Hosted on a free publishing platform namespace (pages.dev) with no verifiable ownership or age
Safety Factors (5)
Page explicitly states its goal is to observe the signing prompt UI, and instructs 'DO NOT APPROVE'
Zero forms: 0 password fields, 0 disguised-password fields, 0 payment fields
No cross-origin credential exfiltration and no cross-origin JS network targets detected
No Indicators of Compromise, no YARA JavaScript malware patterns, no known malicious kit, no Safe Browsing threats
Single external script host (esm.sh), a popular ranked module CDN
Domain age information unavailable

Details

Page Title

Phantom Solana dangerous-payload UX battery

Scan Type

public

Domain Name Analysis

Within the developer-focused generic top-level domain (.dev), 'phantom-mobile-test.pages.dev' is registered with subdomain 'phantom-mobile-test'. The registrable portion 'pages' spans 5 characters with 2 vowels and 3 consonants. Tokenizing the label suggests 1 word: pages. The median word length lands at 5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://phantom-mobile-test.pages.dev/

Page Load Overview

8.60s
Total Load Time
321 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:55%
Script:Latin
Direction:ltr

Detection Details

Text Length:873 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software43% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
43%
documentation technical
31%
finance banking
28%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
24188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
21172.67.70.222Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
21188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
21104.26.14.209Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
21104.26.15.209Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1085--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T17422B7347179107009B720C947B7AB17B37BD01429A88560AACEA02A7F9F13F937B6D6

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:omEEngA00kU3+eQae3on4DnVBdDAe42Bpf1G164+7bKKhH4TxqdnJAj:oDog2kw+eQakaEVBlLzG16YKh/i

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:10521:iVK0iEAMABqAswMBFRFIkAgpJSAkUJKUHQYpgOhQHDTgAsDoYJENiGxQASCySlodRoAUggPMLUOvaBEACAiUAGaHAiBHFDCb

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:f0f8f8f8f8000000
Perceptual Hash:cdcd3636c1c0323f
Difference Hash:40008282100c4000
Wavelet Hash:fcfcfcfcf8c00000
Color Hash:#3a7853

Other Hashes

Crop Resistant:40008282100c4000

Scan History

Scan history not available

Unable to load historical scan data