---
title: "Is phantom-client.com a Scam? Trust Score 5/100"
source: TrustSniffer
type: Website trust & fraud report
subject: "phantom-client.com"
verdict: "Critical Risk"
title: "Is phantom-client.com a Scam? Trust Score 5/100"
trust_score: 5
classification_confidence: 55
canonical_url: https://trustsniffer.com/report/phantom-client.com
assessed: 2026-09-19
---

# Is phantom-client.com a scam? TrustSniffer's high-risk assessment: 5/100

## Verdict


**Verdict: Critical Risk, trust score 5/100.** phantom-client.com shows high-risk / scam indicators.

This assessment found strong scam indicators. Do not pay, sign in, or share personal details with this site.

Labels: Sensitive Interaction Risk, Governance Risk

Assessed 2026-09-19 by automated analysis. Classification confidence 55%.

| Field | Value |
| --- | --- |
| What this site appears to be | A product page offering Phantom Client 26.2 for Fabric: a free, client-side Minecraft PvP/ghost client with modules for combat, movement, render and utility. Provides downloads, installation steps, feature list and FAQ. No account or payment is required. |

## Evidence status and limitations


Evidence completeness: UNKNOWN

- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.

## At a glance

The checks that decide most of this verdict.

| Check | Result | Status |
| --- | --- | --- |
| Malware engines | 5 flagged it (VirusTotal) | Risk |
| Google Safe Browsing | Not listed (Google) | Clear |
| Abuse reports on the host | 0 reports (AbuseIPDB; shared hosting inflates this count) | Noted |
| Domain age | 22 days old (Most scam domains are under a year old) | Risk |
| Web archive | Never archived (No public history of this site) | Watch |
| Certificate | Encrypted connection (Issued by YE2) | Noted |

## The page as captured


![Screenshot of the phantom-client.com homepage captured during the TrustSniffer assessment](https://trustsniffer.com/outputs/phantom-client.com/screenshots/first.png)

_What phantom-client.com served when TrustSniffer captured it on 2026-09-19. The page may look different now._

## Key findings


- Automated classification: Sensitive Interaction Risk.
- Domain age: less than 1 year (registration continuity).
- At least one reputation service TrustSniffer consulted had flagged this domain at assessment time.

## Full analysis


### Security Alert

Fortinet flagged this site in external intelligence checks, indicating elevated compromise/scam exposure that requires immediate caution.

Phantom-client.com presents Phantom Client 26.2 for Fabric as a free downloadable Minecraft client-side modification distributed as a JAR file, with installation guidance, feature documentation, FAQs, credits, and terms for users seeking combat, movement, rendering, and utility modules.


### Scam/Impersonation Risk

The site presents a coherent software-download purpose and does not show login forms, payment collection, or brand-impersonation indicators in the supplied page analysis. However, this benign page behavior is outweighed by confirmed external malicious detections and blacklist status, which create a material risk for downloading or executing the distributed software. The site’s stated product is also a game-modification client containing features such as AimAssist, AutoClicker, Reach, Velocity, HitSelect, and Criticals; that context creates policy and endpoint-security concerns even though it is not, by itself, proof of fraud. No conflicting legal identities or confirmed phishing indicators were observed.


Evidence:
- The home and product pages describe a free JAR-based Minecraft client with combat, movement, render, and utility modules, including AimAssist, AutoClicker, Reach, Velocity, HitSelect, and Criticals.
- The site’s behavioral analysis recorded no login form, hidden sensitive form, external submission, wallet activity, clipboard hijacking, or cloaking.
- External reputation telemetry recorded 5 malicious detections and 1 suspicious detection; a Fortinet detection was present, and the domain was confirmed on external blacklists.
- The domain was registered on 2026-08-28 and is approximately 0.06 years old, according to registration records.

### Regulatory Verification Notes

The legal and identity pages consistently use the name Phantom Client and provide terms of use and a privacy policy, but the supplied content does not independently verify a real-world operating entity or disclose a regulatory authorization. The terms direct questions to community channels rather than identifying a formal corporate contact, and the privacy policy describes collection of standard web-server logs. Independent recognition identifies phantom-client.com as a registered DeFi protocol; the supplied recognition record does not specify its category or provide any TVL, market-cap, or trading-volume figure. That recognition is a positive legitimacy signal for the named protocol record, but it does not neutralize the confirmed blacklist and malicious-detection evidence or establish that the downloadable software is safe.


Evidence:
- The terms page identifies “Phantom Client” as the client provider and governs downloading, installing, and using the software.
- The privacy page states that standard web-server logs, including IP address, browser type, and pages visited, are collected for analytics and security.
- The supplied independent protocol record recognizes “phantom-client.com”; no category or financial magnitude is included in that record.
- The site’s legal and credits pages contain no supplied company registration number, licensing number, or independently verified operator identity.

### What to Verify Next

Any prospective engagement should first confirm the operator and project through an independent, established community or software-distribution channel rather than relying solely on the site’s own pages. The JAR should be subjected to controlled malware analysis and code-signature or hash verification before execution, with execution isolated from production credentials and sensitive systems. If the project makes any regulated financial or DeFi-related representation elsewhere, the relevant authorization and protocol details should be checked against the applicable official registry.


Evidence:
- The terms and privacy pages refer to community channels but do not provide a supplied formal contact identity.
- The FAQ instructs users to download and place the JAR in the Minecraft mods folder, making the software artifact itself the relevant object for independent analysis.
- The supplied recognition record contains no category, TVL, market-cap, or trading-volume detail to validate independently from the record provided.

### Summary Verdict

The overall posture is **critical trust risk**, with sensitive interaction risk driven by confirmed blacklist and malicious-detection signals. Although the site has internally consistent software documentation and is independently recognized as phantom-client.com in a protocol registry, the available evidence is not sufficient to treat the website or its downloadable software as trustworthy for execution or other sensitive interaction.


### Infrastructure Integrity

The site uses Cloudflare CDN/WAF protection, and the observed infrastructure exposes an edge address rather than an independently observable origin; this can reduce direct origin exposure but is only a mitigating control and does not establish legitimacy.


Evidence:
- Hosted on AS203273, NetCraftersOU - NetCrafters OU, EE; the observed server address is 91.211.13.26.
- Cloudflare is identified as the CDN/WAF provider, with 1 observed edge IP and 0 observed origin candidates.
- The site uses a DV TLS certificate issued by YE2, valid to 2026-12-16T17:48:16+00:00.

### Closing Assessment

The appropriate institutional posture is to avoid credential, financial, or production-system interaction and to permit only tightly controlled, read-only investigation until the operator and software artifact have been independently validated.


_Written analysis generated 2026-09-19 by the TrustSniffer Analysis Engine from the evidence in this report._

## What the analysis found

2 findings contributed to this verdict, raised by registration and ownership, analysis engine, external reputation.

### 01 Governance Risk
- Registration details are held behind a privacy service, so no operator is named publicly. This is common and legal, and it also means there is nobody to check. (Registration and ownership `rule:KF_WHOIS_PRIVATE`)

### 02 Sensitive Interaction Risk
- The analysis matched a pattern TrustSniffer treats as a direct threat to a visitor. (Analysis engine `signal:direct_threat`)
- An external threat feed lists this domain: either Google Safe Browsing marked it malicious, or a significant number of malware engines flagged it. (External reputation `rule:EXT_BLACKLIST_CRITICAL`)

## Identity verification


| Field | Value |
| --- | --- |
| Status | LIKELY |
| Identity score | 70/100 |
| Identity verification confidence | 36% |

- org:Phantom Client
- on_site_identity

_Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence._

## What TrustSniffer observed

First-party facts recorded during the assessment of phantom-client.com.

- The request stayed on phantom-client.com. It was not redirected to another domain. (Clear)
- Registration is published under Internet Domain Service BS Corp.. (Clear)
- DNS for this domain is served by cloudflare.com, across 2 name servers. (Noted)
- The registration is paid up to 2027-08-28. (Noted)
- It is hosted on NetCraftersOU, from a server in UA. (Noted)

## Domain intelligence


| Field | Value |
| --- | --- |
| Registrar | Internet Domain Service BS Corp. |
| Hosting | NetCraftersOU - NetCrafters OU, EE |
| Country | UA |
| Server IP | 91.211.13.26 |
| Name servers | ANDY.NS.CLOUDFLARE.COM, BRENNA.NS.CLOUDFLARE.COM |
| SSL issuer | YE2 |
| SSL expiry | 2026-12-16 |
| Domain age | 0.06 years (continuous registration) |
| Domain expiry | 2027-08-28 |
| Archive first seen | Not available |
| Archive snapshots | 0 |
| Reputation | VirusTotal: 5 flagged \| AbuseIPDB: 0 reports \| Google Safe Browsing: 0 matches |

## About this assessment


A trust score summarises the evidence TrustSniffer could collect about phantom-client.com at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.

TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.

## Related on TrustSniffer
- [mrpalace.com risk report](https://trustsniffer.com/report/mrpalace.com) (Critical Risk, 0/100)
- [blupeakadvisors.com risk report](https://trustsniffer.com/report/blupeakadvisors.com) (Critical Risk, 5/100)
- [hamrokhata.com risk report](https://trustsniffer.com/report/hamrokhata.com) (Critical Risk, 5/100)
- [ayorindethomasandco.com risk report](https://trustsniffer.com/report/ayorindethomasandco.com) (Critical Risk, 0/100)
- [englishplusmore.com risk report](https://trustsniffer.com/report/englishplusmore.com) (Critical Risk, 0/100)
- [mstsistema.com risk report](https://trustsniffer.com/report/mstsistema.com) (Critical Risk, 0/100)
- [d-koresolar.com risk report](https://trustsniffer.com/report/d-koresolar.com) (Critical Risk, 0/100)
- [1207f.com risk report](https://trustsniffer.com/report/1207f.com) (Critical Risk, 0/100)
- [11775357.com risk report](https://trustsniffer.com/report/11775357.com) (Critical Risk, 0/100)
- [113acessorios.com.br risk report](https://trustsniffer.com/report/113acessorios.com.br) (Critical Risk, 0/100)
- [Every website and wallet TrustSniffer has assessed](https://trustsniffer.com/directory)
- [Other domains assessed as high-risk or phishing](https://trustsniffer.com/directory/phishing-domains)
- [Check another website](https://trustsniffer.com/web-intelligence)
- [Check a crypto wallet address](https://trustsniffer.com/on-chain-risk)
- [The TrustSniffer Risk Index](https://trustsniffer.com/stats)

## Guides
- [Stablecoin Freezes Sep 25, 2026: 8 Wallets](https://trustsniffer.com/blog/stablecoin-freeze-report-2026-09-25)
- [VietinBank Phishing: Spotting Domain Impersonation](https://trustsniffer.com/blog/vietinbank-phishing-domain-impersonation)
- [Stablecoin Freezes, Sep 24, 2026: 26 Wallets](https://trustsniffer.com/blog/stablecoin-freeze-report-2026-09-24)

---
*Source: [TrustSniffer](https://trustsniffer.com/report/phantom-client.com) — independent automated trust & fraud analysis. Cite as https://trustsniffer.com/report/phantom-client.com · assessed 2026-09-19.*
