Verdict
phantom-client.com shows high-risk / scam indicators.
This assessment found strong scam indicators. Do not pay, sign in, or share personal details with this site.
| What this site appears to be | A product page offering Phantom Client 26.2 for Fabric: a free, client-side Minecraft PvP/ghost client with modules for combat, movement, render and utility. Provides downloads, installation steps, feature list and FAQ. No account or payment is required. |
|---|
Evidence status and limitations
Evidence completeness: UNKNOWN
- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.
At a glance
The checks that decide most of this verdict.
| Malware engines | 5 flagged itVirusTotal | Risk |
|---|---|---|
| Google Safe Browsing | Not listedGoogle | Clear |
| Abuse reports on the host | 0 reportsAbuseIPDB; shared hosting inflates this count | Noted |
| Domain age | 22 days oldMost scam domains are under a year old | Risk |
| Web archive | Never archivedNo public history of this site | Watch |
| Certificate | Encrypted connectionIssued by YE2 | Noted |
The page as captured
Key findings
- Automated classification: Sensitive Interaction Risk.
- Domain age: less than 1 year (registration continuity).
- At least one reputation service TrustSniffer consulted had flagged this domain at assessment time.
Full analysis
Security Alert
Fortinet flagged this site in external intelligence checks, indicating elevated compromise/scam exposure that requires immediate caution.
Phantom-client.com presents Phantom Client 26.2 for Fabric as a free downloadable Minecraft client-side modification distributed as a JAR file, with installation guidance, feature documentation, FAQs, credits, and terms for users seeking combat, movement, rendering, and utility modules.
Scam/Impersonation Risk
The site presents a coherent software-download purpose and does not show login forms, payment collection, or brand-impersonation indicators in the supplied page analysis. However, this benign page behavior is outweighed by confirmed external malicious detections and blacklist status, which create a material risk for downloading or executing the distributed software. The site’s stated product is also a game-modification client containing features such as AimAssist, AutoClicker, Reach, Velocity, HitSelect, and Criticals; that context creates policy and endpoint-security concerns even though it is not, by itself, proof of fraud. No conflicting legal identities or confirmed phishing indicators were observed.
- The home and product pages describe a free JAR-based Minecraft client with combat, movement, render, and utility modules, including AimAssist, AutoClicker, Reach, Velocity, HitSelect, and Criticals.
- The site’s behavioral analysis recorded no login form, hidden sensitive form, external submission, wallet activity, clipboard hijacking, or cloaking.
- External reputation telemetry recorded 5 malicious detections and 1 suspicious detection; a Fortinet detection was present, and the domain was confirmed on external blacklists.
- The domain was registered on 2026-08-28 and is approximately 0.06 years old, according to registration records.
Regulatory Verification Notes
The legal and identity pages consistently use the name Phantom Client and provide terms of use and a privacy policy, but the supplied content does not independently verify a real-world operating entity or disclose a regulatory authorization. The terms direct questions to community channels rather than identifying a formal corporate contact, and the privacy policy describes collection of standard web-server logs. Independent recognition identifies phantom-client.com as a registered DeFi protocol; the supplied recognition record does not specify its category or provide any TVL, market-cap, or trading-volume figure. That recognition is a positive legitimacy signal for the named protocol record, but it does not neutralize the confirmed blacklist and malicious-detection evidence or establish that the downloadable software is safe.
- The terms page identifies “Phantom Client” as the client provider and governs downloading, installing, and using the software.
- The privacy page states that standard web-server logs, including IP address, browser type, and pages visited, are collected for analytics and security.
- The supplied independent protocol record recognizes “phantom-client.com”; no category or financial magnitude is included in that record.
- The site’s legal and credits pages contain no supplied company registration number, licensing number, or independently verified operator identity.
What to Verify Next
Any prospective engagement should first confirm the operator and project through an independent, established community or software-distribution channel rather than relying solely on the site’s own pages. The JAR should be subjected to controlled malware analysis and code-signature or hash verification before execution, with execution isolated from production credentials and sensitive systems. If the project makes any regulated financial or DeFi-related representation elsewhere, the relevant authorization and protocol details should be checked against the applicable official registry.
- The terms and privacy pages refer to community channels but do not provide a supplied formal contact identity.
- The FAQ instructs users to download and place the JAR in the Minecraft mods folder, making the software artifact itself the relevant object for independent analysis.
- The supplied recognition record contains no category, TVL, market-cap, or trading-volume detail to validate independently from the record provided.
Summary Verdict
The overall posture is critical trust risk, with sensitive interaction risk driven by confirmed blacklist and malicious-detection signals. Although the site has internally consistent software documentation and is independently recognized as phantom-client.com in a protocol registry, the available evidence is not sufficient to treat the website or its downloadable software as trustworthy for execution or other sensitive interaction.
Infrastructure Integrity
The site uses Cloudflare CDN/WAF protection, and the observed infrastructure exposes an edge address rather than an independently observable origin; this can reduce direct origin exposure but is only a mitigating control and does not establish legitimacy.
- Hosted on AS203273, NetCraftersOU - NetCrafters OU, EE; the observed server address is 91.211.13.26.
- Cloudflare is identified as the CDN/WAF provider, with 1 observed edge IP and 0 observed origin candidates.
- The site uses a DV TLS certificate issued by YE2, valid to 2026-12-16T17:48:16+00:00.
Closing Assessment
The appropriate institutional posture is to avoid credential, financial, or production-system interaction and to permit only tightly controlled, read-only investigation until the operator and software artifact have been independently validated.
Written analysis generated 2026-09-19 by the TrustSniffer Analysis Engine from the evidence in this report.
What the analysis found
2 findings contributed to this verdict, raised by registration and ownership, analysis engine, external reputation.
01 Governance Risk
- Registration details are held behind a privacy service, so no operator is named publicly. This is common and legal, and it also means there is nobody to check.Registration and ownership
rule:KF_WHOIS_PRIVATE
02 Sensitive Interaction Risk
- The analysis matched a pattern TrustSniffer treats as a direct threat to a visitor.Analysis engine
signal:direct_threat - An external threat feed lists this domain: either Google Safe Browsing marked it malicious, or a significant number of malware engines flagged it.External reputation
rule:EXT_BLACKLIST_CRITICAL
Identity verification
| Status | LIKELY |
|---|---|
| Identity score | 70/100 |
| Identity verification confidence | 36% |
- org:Phantom Client
- on_site_identity
Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence.
What TrustSniffer observed
First-party facts recorded during the assessment of phantom-client.com.
- The request stayed on phantom-client.com. It was not redirected to another domain. Clear
- Registration is published under Internet Domain Service BS Corp.. Clear
- DNS for this domain is served by cloudflare.com, across 2 name servers. Noted
- The registration is paid up to 2027-08-28. Noted
- It is hosted on NetCraftersOU, from a server in UA. Noted
Domain intelligence
| Registrar | Internet Domain Service BS Corp. |
|---|---|
| Hosting | NetCraftersOU - NetCrafters OU, EE |
| Country | UA |
| Server IP | 91.211.13.26 |
| Name servers | ANDY.NS.CLOUDFLARE.COM, BRENNA.NS.CLOUDFLARE.COM |
| SSL issuer | YE2 |
| SSL expiry | 2026-12-16 |
| Domain age | 0.06 years (continuous registration) |
| Domain expiry | 2027-08-28 |
| Archive first seen | Not available |
| Archive snapshots | 0 |
| Reputation | VirusTotal: 5 flagged | AbuseIPDB: 0 reports | Google Safe Browsing: 0 matches |
About this assessment
A trust score summarises the evidence TrustSniffer could collect about phantom-client.com at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.
TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.