⚠ DEMO MODE — Example investigation, no live agent has run. All findings, sources, and verdicts shown below are fabricated for UI demonstration.
← All investigations
INVESTIGATION
example-phishing-001

http://paypa1-secure-login.tk/verify

5/16/2026, 2:22:11 PM· 13.14s wall· 4 tool calls· claude-sonnet-4-6· prompt investigation@2026-05-16-1
VERDICTMALICIOUS·Confidence: Very high(92%)

This URL is a credential-harvesting phishing page impersonating PayPal. The domain is on a low-trust TLD (.tk), uses a typosquatted brand name (paypa1 instead of paypal), serves over HTTP without encryption, and 4 of 7 consulted threat-intel sources independently flag the host as malicious.

⚠ WHY IT MATTERS

If you enter a password on this page, attackers harvest the credentials and use them to log into your real PayPal account within minutes — often before you notice.

→ RECOMMENDED NEXT STEP
1Do not click this link or share it. It will harvest credentials.
3 more recommended actions below
SOURCES CONSULTED
7
6 available
REASONING STEPS
5
13.14s total
FINDINGS
6
4 high+critical
WHY WE REACHED THIS VERDICT

We checked this URL against six independent signals. The strongest evidence was a typosquatted brand name combined with a .tk hosting TLD — both patterns that legitimate businesses simply do not use. Four antivirus engines on VirusTotal independently flagged the URL, and the hosting IP has been seen by other ThreatAI users serving phishing pages this month. No source disagreed with the malicious verdict; one source (WHOIS) couldn't contribute because .tk hides registration data, which we accounted for by not weighting it. The verdict is 'malicious' with very high confidence (92%). If you got this link in an email, report it and don't click. If you already entered a password, rotate it and turn on two-factor authentication.

FINDINGS

CRITICAL

Typosquatted brand impersonation

from step 1

Hostname contains 'paypa1' (digit 1 substituted for letter l) — a classic visual-spoof pattern for PayPal.

HIGH

Low-trust TLD (.tk)

from step 1

The .tk TLD is free to register and heavily abused for short-lived phishing infrastructure.

HIGH

No HTTPS

from step 1

Page is served plain HTTP. Legitimate financial logins use TLS in 100% of cases.

HIGH

Multiple AV engines flag the URL

from step 2

VirusTotal reports 4/89 engines (4.5%) classified this URL as malicious or phishing. Low-volume detections in this category are still meaningful for fresh phishing kits.

MEDIUM

Hosting IP has minor abuse history

from step 3

Resolved IP 185.234.219.42 has an AbuseIPDB confidence score of 32% from 7 reports in the last 90 days.

INFO

Domain age unknown via WHOIS

from step 4

.tk WHOIS does not expose registration dates publicly — common evasion. Domain freshness could not be confirmed.

SOURCES CONSULTED

Each source carried a weight in the final confidence score. Sources marked "no data" or "n/a" contributed nothing — they couldn't skew the verdict either way.

Structural analyzer
4 high-severity structural signals
flaggedw=0.25
VirusTotal
4/89 engines flagged
flaggedw=0.30
AbuseIPDB
hosting IP 32% abuse confidence
flaggedw=0.15
Federated graph
3 community sightings of hosting IP
flaggedw=0.20
Memory (corrections)
no user override for this target or pattern
w=0.10
WHOIS
.tk does not expose registration dates
no data
HIBP
not relevant for URL targets

REASONING TIMELINE

The full step-by-step trace. Inputs are summarized and redacted where sensitive; full payloads stay in your account and can be deleted per row.

STEP 1PHISHING4 findings: HTTP-not-HTTPS (high), .tk TLD (high), brand impersonation 'paypa1' (critical), credential-page path (info).18msHIGH
WHY THIS STEP
Run the structural URL analyzer first — it's free, fast, and produces strong signal on typosquatting + TLD risks.
INPUT
URL: http://paypa1-secure-login.tk/verify
OUTPUT
4 findings: HTTP-not-HTTPS (high), .tk TLD (high), brand impersonation 'paypa1' (critical), credential-page path (info).
STEP 2PHISHING4/89 engines flagged as malicious or phishing. Categories returned: 'phishing', 'malicious'. Reputation score: -42.4.18sHIGH
WHY THIS STEP
Cross-reference with VirusTotal. Structural patterns alone aren't enough; a real reputation lookup catches kits with novel structure but flagged history.
INPUT
VirusTotal URL lookup (base64-encoded URL ID)
OUTPUT
4/89 engines flagged as malicious or phishing. Categories returned: 'phishing', 'malicious'. Reputation score: -42.
STEP 3IPAbuse confidence 32%, 7 reports, ISP listed as 'Stark Industries Solutions Ltd', usage type 'Data Center'. Not whitelisted.1.24sMEDIUM
WHY THIS STEP
Resolve the hostname and check the hosting IP's abuse history. Phishing kits cluster on known bad infrastructure.
INPUT
DNS → 185.234.219.42; AbuseIPDB check, 90-day window.
OUTPUT
Abuse confidence 32%, 7 reports, ISP listed as 'Stark Industries Solutions Ltd', usage type 'Data Center'. Not whitelisted.
STEP 4GRAPH_LOOKUPURL hash: not seen in last 30 days (k-anon floor not yet reached). IP hash: 3 community observations in last 14 days, all flagged 'phishing-host'.1.71sHIGH
WHY THIS STEP
Check the federated threat graph for prior community sightings of either the URL or its hosting IP.
INPUT
SHA-256(hostname) prefix lookup; SHA-256(ip) lookup.
OUTPUT
URL hash: not seen in last 30 days (k-anon floor not yet reached). IP hash: 3 community observations in last 14 days, all flagged 'phishing-host'.
STEP 5REASONINGVerdict: malicious, confidence 0.92. Sources in agreement (structural + VT + graph). Hosting IP soft-corroborates. Recommendation list assembled.4.64s
WHY THIS STEP
Synthesize the findings into a verdict. Compose confidence from source consensus and historical accuracy.
INPUT
Findings from steps 1–4 + memory recall of similar past verdicts.
OUTPUT
Verdict: malicious, confidence 0.92. Sources in agreement (structural + VT + graph). Hosting IP soft-corroborates. Recommendation list assembled.

WHAT DATA LEFT YOUR DEVICE

One row per third-party touched. We name every destination and what we sent.

VirusTotal
URL
Hashed URL ID via VT API.
OUTBOUND
AbuseIPDB
IPv4 address
Hosting IP resolved by local DNS.
OUTBOUND
Federated graph
SHA-256 hash prefixes
Hostname + IP hashed before lookup. Raw values never sent.
OUTBOUND
Anthropic Claude
Findings + reasoning prompt
Step summaries only. No user-identifying data.
OUTBOUND
local
Full step + tool payloads
Stored in your account; deletable per row.
STAYED LOCAL

RUN BUDGET

We show what your investigation cost in tokens and dollars — same number we charge against your quota.

TOOL CALLS
4
TOKENS IN
3,840
TOKENS OUT
612
WALL CLOCK
13.14s
COST (USD)
$0.013