Last updated: · By

Onion Page Pivot Extractor: Onion Addresses, PGP, Wallets, Analytics IDs

A saved onion page usually reveals more than its address: PGP fingerprints, Bitcoin and Monero wallets, contact emails and Jabber IDs, Google Analytics or AdSense IDs reused from clearnet sites, mirror lists, and sometimes a server banner that names a real host. Paste the source you saved in Tor Browser, or drop the .html/.txt files, and this tool extracts every pivotable identifier, checks v3 onion addresses against the Tor specification’s SHA3-256 checksum, flags dead v2 addresses and look-alike phishing mirrors, validates wallet checksums and builds lookup links. It runs entirely in your browser and never visits the onion site.

Paste only material you collected lawfully; this tool does not visit onion sites. It reads the page source or text you saved yourself, entirely in this browser tab: nothing is uploaded, scripts in the pasted HTML never run and its images are never loaded. Stay on public information, never log in to or interact with illegal marketplaces, never paste illegal content, keep notes of how you collected the page, and involve legal counsel for sensitive work — see the legal and ethical guardrails in our dark-web OSINT guide.
Drop saved .html / .txt files here or press Enter to choose files — several files at once, up to 5 MB each are scanned

    Ctrl/Cmd+Enter in the box or the Extract button runs it · HTML is parsed as an inert document (no scripts, no images) and also scanned as raw text · clearnet URLs are shown as text, never as clickable links · lookup links open third-party sites only when you click them.

    Favicon hash (optional)

    Save the site's favicon from Tor Browser and drop the file here. The Shodan-style hash and SHA-256 are computed locally; the icon is never fetched.

    Drop favicon file (.ico, .png, .svg…) or press Enter to choose

    What does the extractor find, at a glance?

    Every row below is extracted from the text you paste or the files you drop, deduplicated and counted, with up to five “where found” snippets (file, line number, surrounding text). Results are grouped, each group can be copied, and the whole set exports to CSV or JSON.

    IdentifierHow it is foundCheckLookup linksSource
    v3 onion address56 base32 characters + .onionSHA3-256 checksum and version byte 0x03; look-alike prefix/suffix testAhmia (paste), Google exact matchTor Specifications: rend-spec, “Encoding onion addresses [ONIONADDRESS]” (read 10 Oct 2026)
    v2 onion address16 base32 characters + .onionFlagged as dead legacy formatAhmia (paste)Tor Project blog: “Onion Service version 2 deprecation timeline”, dgoulet (2 Jul 2020)
    Bitcoin1…, 3…, bc1q…, bc1p…Base58Check double SHA-256; bech32 / bech32m checksum and witness rulesmempool.space, Blockstream, Blockchair, Crypto OSINTBitcoin Wiki: Base58Check encoding — double-SHA-256 checksum, version bytes 0 and 5 (read 10 Oct 2026) BIP-173: Base32 address format for native v0-16 witness outputs (assigned 20 Mar 2017) BIP-350: Bech32m format for v1+ witness addresses (assigned 16 Dec 2020)
    Ethereum / EVM0x + 40 hexEIP-55 mixed-case checksum when mixed caseEtherscan, Blockchair, Crypto OSINTEIP-55: Mixed-case checksum address encoding (created 14 Jan 2016)
    Monero95 characters starting 4 or 8 (106 for integrated)Keccak-256 checksum, network byteCrypto OSINT (no public balance)Monero Docs: Standard address — 95 characters, network byte 18, Keccak-256 checksum (read 10 Oct 2026)
    PGPArmored blocks; labelled 40/64-hex fingerprints; key IDsDetection only; parse in the PGP Key InspectorPGP Key Inspector, keys.openpgp.orgRFC 9580 OpenPGP (Jul 2024): 8-octet Key IDs; 20-octet v4 and 32-octet v6 fingerprints
    Email, XMPP, Telegram, Matrix, Session, ToxAddresses, xmpp:, t.me/, labelled @handles, @user:serverTox XOR checksum; context labels for ambiguous formsEmail OSINT, keys.openpgp.org, t.me, matrix.toTokTok Tox spec: Tox ID = 32-byte key + 4-byte nospam + 2-byte XOR checksum (read 10 Oct 2026) Matrix spec: User identifiers @localpart:domain; matrix.to URIs (read 10 Oct 2026)
    Analytics & ad IDsUA-, G-, GTM-, ca-pub-, AW-, Meta pixel, Yandex MetricaPattern + script contextPublicWWW, Shodan http.html, Censys full-textShodan: search filter reference — http.favicon.hash, http.html, http.title (read 10 Oct 2026) PublicWWW: source-code search, /websites/"…"/ query URL (vendor page; checked 10 Oct 2026)
    Server banners, title, generatorApache/2.4.x, “Server at … Port”, <title>, <meta name=generator>Non-onion host in a signature flagged as a possible leakShodan, Censys html_title, Domain / IP OSINTShodan Help Center: Search Query Fundamentals — search?query= URL examples (read 10 Oct 2026) Censys docs: Censys Query Language — full-text search, favicons.hash_sha256, html_title example (read 10 Oct 2026)
    Clearnet domains, IPs, phoneshttp(s) URLs, IPv4/IPv6, +international numbersPrivate ranges marked; CDN domains optionalDomain, IP and Phone OSINT, Shodan host—
    FaviconThe icon file you dropMurmurHash3 of MIME base64 (Shodan) + SHA-256Shodan http.favicon.hash, Censys favicon SHA-256Shodan blog: “Deep Dive: http.favicon” — MurmurHash3 of the base64 favicon data (read 10 Oct 2026)

    What can a saved onion page reveal about its operator?

    Onion services hide where a server is, not what its operator publishes. A saved page often carries identifiers that also exist outside Tor:

    • Payment addresses. Bitcoin and Ethereum addresses are public on their blockchains, so a donation or escrow address can be followed to exchanges and other sites. Monero is different: its addresses do not expose balances or counterparties to block explorers.
    • PGP keys. Vendors and administrators sign mirror lists and messages. The same fingerprint on another forum, a paste site or a key server links the identities. Paste an armored block into the PGP Key Inspector to read its fingerprint, user IDs and creation date.
    • Contact handles. Email, Jabber/XMPP, Telegram, Matrix, Session and Tox IDs are frequently reused across sites. Search them on the clearnet before anything else.
    • Analytics, ad and verification IDs. A Google Analytics, Tag Manager, AdSense or Yandex Metrica ID, or a site-verification token, copied from an operator's clearnet template is a classic attribution pivot. Source-code search engines such as PublicWWW index these strings across websites (vendor description).
    • Server leaks. Apache and nginx error pages can print a signature such as Server at 203.0.113.7 Port 80, and absolute links can name a clearnet domain or IP. The extractor flags any non-onion host in a server signature.
    • Other onion services. Mirror lists, links to partner shops and “official” directories show which services the operator controls or trusts, and the extractor separates the page's own address from addresses it links to.

    None of these is proof on its own. Operators plant decoys, share templates and copy each other's pages, so treat each hit as a lead to corroborate, as our dark-web OSINT guide recommends for any onion link.

    How are v3 onion addresses checked?

    The Tor specification defines a v3 onion address as base32(PUBKEY | CHECKSUM | VERSION) + ".onion", where PUBKEY is the service's 32-byte ed25519 public key, VERSION is one byte with the value 3, and CHECKSUM is the first two bytes of SHA3_256(".onion checksum" | PUBKEY | VERSION) Tor Specifications: rend-spec, “Encoding onion addresses [ONIONADDRESS]” (read 10 Oct 2026). Those 35 bytes encode to exactly 56 base32 characters, which matches the Tor Project's description of an onion address as 56 letters and numbers followed by .onion Tor Project Support: Onion Services — 16-character v2 addresses “no longer work”, onion addresses have 56 characters (read 10 Oct 2026).

    The extractor decodes each 56-character label, checks that the version byte is 3, recomputes the SHA3-256 checksum with its own built-in SHA3 implementation (no library is downloaded) and marks the address valid or invalid with the reason. It was tested against the three example addresses printed in the specification and against addresses generated from random 32-byte keys with the same algorithm.

    What the checksum proves is narrow: the address is well-formed and was not mistyped. It does not prove that the service is online, that it is the site it claims to be, or that whoever wrote the page controls it.

    Why flag v2 addresses and look-alike mirrors?

    v2 addresses are dead. The Tor Project's timeline removed v2 onion services from the code base in the 0.4.6 series (July 2021) and shipped client releases that disabled v2 on 15 October 2021 Tor Project blog: “Onion Service version 2 deprecation timeline”, dgoulet (2 Jul 2020). Its support pages say 16-character v2 addresses no longer work Tor Project Support: Onion Services — 16-character v2 addresses “no longer work”, onion addresses have 56 characters (read 10 Oct 2026). A 16-character address on a page is a dating clue — the text, or the link list it was copied from, predates the switch.

    Look-alikes. When two v3 addresses on the same page share their first five or more characters, or four or more characters at the end (ignoring the final two, which carry the version), both are flagged as possible phishing clones. Random v3 addresses almost never share that much by chance; matching prefixes are usually generated on purpose so that a mirror looks familiar at a glance. Check every character against a source you trust, such as a PGP-signed mirror list.

    Labels of other lengths ending in .onion are listed as malformed: truncated, padded or deliberately broken links.

    How are wallet addresses validated?

    Base58 strings that fail the checksum are shown only when they look like an address and the surrounding text mentions Bitcoin, a wallet, payment or donation, so random tokens do not flood the results. Lookup links are offered only for addresses that pass.

    How does the favicon hash work?

    Shodan stores each site's favicon as base64 data and computes http.favicon.hash by applying MurmurHash3 to that data; its own example shows the base64 broken into lines of 76 characters Shodan blog: “Deep Dive: http.favicon” — MurmurHash3 of the base64 favicon data (read 10 Oct 2026). The commonly used reproduction is mmh3.hash(base64.encodebytes(data)) SANS ISC diary: “Adding some Automation to the favicon.ico method of Host Recon”, Rob VandenBrink (29 Jun 2026), where encodebytes inserts a newline after every 76 characters and ends with a trailing newline Python docs: base64.encodebytes — newline every 76 bytes plus a trailing newline (read 10 Oct 2026) and mmh3.hash returns the signed 32-bit MurmurHash3_x86_32 value with seed 0 mmh3 API docs: hash(key, seed=0, signed=True), MurmurHash3_x86_32 (read 10 Oct 2026).

    This page implements exactly that in JavaScript. We cross-checked it against the Python mmh3 package on 300 random files and two real icons (identical results, including negative values). It also shows the file's SHA-256, because the Censys Query Language lists a favicons.hash_sha256 field Censys docs: Censys Query Language — full-text search, favicons.hash_sha256, html_title example (read 10 Oct 2026).

    FOFA also offers icon search, but its syntax documentation could not be read from our test environment, so the FOFA button opens its home page for you to paste the hash rather than a pre-filled search we could not verify.

    Which lookup links does it build, and how were they checked?

    Every link puts the value through encodeURIComponent, opens in a new tab with rel="noopener", and uses a URL format confirmed from the vendor's documentation or by loading it on 10 October 2026:

    Clearnet URLs found on the page are shown as plain text, never as clickable links, so you cannot open a hostile link by accident. Clicking any lookup sends that one value to that third-party site.

    Is the pasted page sent anywhere?

    No. Text and files are read with the browser's FileReader and scanned in this tab. To read the title, meta tags, favicon references and link targets, the HTML is parsed with DOMParser as an inert text/html document: it is never added to this page, its scripts do not run and its images, frames and stylesheets are not requested. Everything shown is escaped as text. Inputs over 5 MB per file are cut to the first 5 MB (20 MB in total); the structural HTML parse covers the first 2 MB of each file while the pattern scan covers all of it, and the work is split into steps so the tab stays responsive. Nothing is stored after you close the tab.

    Accessing the dark web is legal in most jurisdictions and many onion services are legitimate, from secure communications to whistleblowing platforms. What crosses the line is engaging in illegal activity, such as buying illicit goods, downloading criminal material or infiltrating criminal networks without authorisation. Stay on public information, never interact with illegal marketplaces or enter credentials, document your methodology, and involve legal counsel for anything sensitive, as set out in our dark-web OSINT guide. Never paste illegal content, such as child sexual abuse material, into any tool; report it to the authorities instead.

    How was the extractor tested?

    • SHA3-256 and SHA-256 against Node.js's built-in hashes for inputs of 0 to 5,000 bytes, including the 135/136/137-byte block boundaries; Keccak-256 through the eight EIP-55 test vectors.
    • The three v3 addresses printed in the Tor specification, 50 addresses generated from random keys, and one-character mutations of each (all rejected).
    • BIP-173 and BIP-350 valid and invalid vectors, the Bitcoin genesis address, a P2SH address, the Monero docs' example address, and random Tox IDs.
    • The favicon hash against Python's mmh3 on 300 random inputs.
    • A synthetic saved page in headless Chromium: expected counts and valid/invalid marks per group, look-alike and v2 flags, no page errors, scripts in the pasted HTML never executed, no image requests, no horizontal scrolling at 375 px, and a 5 MB paste completed with progress updates.

    Sources

    Shodan, Censys, PublicWWW and Ahmia descriptions are vendor statements. Lookup links go to third-party sites, which receive whatever value you click.

    Frequently asked questions

    Does this tool connect to the onion site?

    No. It only reads the text or files you give it. Pasted HTML is parsed as an inert document with the browser's DOMParser, so its scripts never run, its images and stylesheets are never requested, and nothing is inserted into this page. The only network requests happen if you click a lookup link, which opens a third-party site in a new tab.

    How do I save an onion page for analysis?

    In Tor Browser, open the page and press Ctrl+U (Cmd+U on a Mac) to view the source, then copy it, or use File > Save Page As and choose a web page or text file. Paste the source or drop the saved .html or .txt files here; several files can be dropped at once. Record the URL, the time and how you reached the page for your notes.

    How can I tell if a v3 onion address is genuine?

    Every v3 address is 56 base32 characters that encode the service's 32-byte ed25519 public key, a 2-byte checksum and a version byte of 3. The checksum is the first two bytes of SHA3-256 over the string ".onion checksum", the key and the version. A changed character almost always breaks it, so an invalid result means a typo or a deliberately broken link. A valid checksum only proves the address is well-formed, not that it belongs to the site you think it does.

    Why are 16-character onion addresses flagged?

    Those are legacy v2 onion addresses. The Tor Project removed v2 support in Tor 0.4.6 and released client versions that disabled v2 on 15 October 2021, so these addresses no longer work. Finding one usually means the page or link list is old or copied from an old source.

    What does the look-alike warning mean?

    It appears when two v3 addresses on the same page share their first five or more characters, or a run of characters at the end. Phishing clones of dark-web sites often copy the start of a real address because people tend to check only the first few characters. Compare every character against a source you trust before relying on either address.

    How is the Shodan favicon hash calculated?

    Shodan applies MurmurHash3 to the base64-encoded favicon data, and the base64 has a line break every 76 characters plus one at the end, the format Python's base64.encodebytes produces. This page computes the same signed 32-bit MurmurHash3 value in your browser, together with the SHA-256 of the file, which Censys indexes as a favicon hash. Drop the icon file you saved from the page; the tool never downloads it.

    Why would an onion page leak a clearnet IP address or domain?

    Misconfigured servers can show their real address in an Apache or nginx error-page signature such as "Server at 203.0.113.7 Port 80", in absolute links, or in analytics and ad IDs reused from the operator's clearnet sites. The extractor flags these, but treat them as leads: operators also plant decoy addresses, so confirm with independent evidence before acting.

    Is it legal to analyse a saved onion page?

    Reading and analysing material you collected lawfully is generally legal, and many onion services are legitimate. What crosses the line is engaging in illegal activity, such as buying illicit goods or downloading criminal material. Do not paste illegal content, stay on public information, document your method, and involve legal counsel for sensitive work.