Is 10mais.com.br a scam? TrustSniffer's high-risk assessment: 0/100

10mais.com.br
Download PDF Check another site How we score

Verdict

0 OUT OF 100
Critical Risk

10mais.com.br shows high-risk / scam indicators.

This assessment found strong scam indicators. Do not pay, sign in, or share personal details with this site.

Sensitive Interaction Risk Governance Risk

Assessed 2026-08-18 by automated analysis. Classification confidence 70%.

What this site appears to beMinimal Portuguese-language parked domain page stating the domain is available and inviting proposals via an email address. No forms, links, or additional service claims are present.

Evidence status and limitations

Evidence completeness: UNKNOWN

  • The real-world operator identity was not independently verified.
  • Module-level completeness metadata is unavailable for this legacy report.

At a glance

The checks that decide most of this verdict.

Malware engines4 flagged itVirusTotalRisk
Google Safe BrowsingNot listedGoogleClear
Abuse reports on the host0 reportsAbuseIPDB; shared hosting inflates this countNoted
Domain age27 years oldRegistered historyClear
Web archiveArchived since 200049 snapshotsClear
CertificateEncrypted connectionIssued by YR2Noted

The page as captured

https://10mais.com.br/
Screenshot of the 10mais.com.br homepage captured during the TrustSniffer assessment
What 10mais.com.br served when TrustSniffer captured it on 2026-08-18. The page may look different now.

Key findings

  • Automated classification: Sensitive Interaction Risk.
  • Domain age: more than 10 years (registration continuity).
  • Public web-archive history exists since 2000.
  • At least one reputation service TrustSniffer consulted had flagged this domain at assessment time.

Full analysis

Security Alert

Fortinet flagged this site in external intelligence checks, indicating elevated compromise/scam exposure that requires immediate caution.

The website is a minimal Portuguese-language parked-domain page for 10mais.com.br. It states that the domain is available, offers it freely to projects selected by the owner or accepts proposals, and presents no operational service, account area, or commercial product beyond a possible domain transfer or sale.

Scam/Impersonation Risk

The site carries a critical sensitive-interaction risk because multiple external reputation checks produced malicious or blacklist detections, including four malicious and one suspicious classification and a Tier-1 security-vendor detection. The blacklist status is a confirmed contradiction requiring a security-forward posture, even though the homepage itself is only a static domain-sale page with no login form, payment flow, hidden form, wallet connection, or brand-impersonation indicators. The domain’s long registration continuity and historical archive presence are establishment signals, but they do not neutralize the external threat detections or independently verify the current operator’s identity.

Evidence
  • External reputation checks recorded 4 malicious and 1 suspicious detections; blacklist status was recorded by 2 sources, with Fortinet among the flagged vendors.
  • The homepage is a 145-character parked-domain page stating “Domínio Disponível” and offering the domain for projects or proposals, with no login, payment, or sensitive-data form.
  • Domain registration dates to 1999-11-11, making it approximately 26.79 years old.
  • Historical records contain 49 snapshots from 2000-10-18 through 2025-02-19, covering 26 tracked years.

Regulatory Verification Notes

The page presents a personal domain-sale or transfer arrangement rather than a regulated financial, brokerage, or investment service. It makes no licensing claim and provides no license number, corporate disclosure, terms, or regulatory attribution; this is a transparency gap for any party considering a commercial transaction, although it is not by itself evidence of fraud. The available evidence does not independently verify the real-world operator behind the page. A separate broker-reputation dataset produced no match, which is contextual only and does not establish licensing or legitimacy.

Evidence
  • The homepage describes domain availability and proposal-based transfer or sale, with no regulated-service description.
  • No license authority, registration number, terms page, or corporate identity disclosure is presented on the available site page.
  • The site is served from AS31898, identified as ORACLE-BMC-31898 – Oracle Corporation, US.
  • The transport certificate is issued by YR2, uses DV validation, and is valid through 2026-10-25T00:42:40+00:00.

What to Verify Next

Before any transaction, an interested party should independently confirm that the domain holder controls the transfer process, validate the payment and escrow arrangements through an established provider, and confirm the official contact channel through an offline or independently sourced route. Any proposed change from a domain-sale interaction to account access, credential submission, software download, or financial activity should be treated as a material change in risk and reassessed separately.

Evidence
  • The homepage contains no transaction workflow, escrow terms, identity documentation, or formal purchase conditions.
  • The available page contains no independent corporate, licensing, or regulatory reference against which the proposed counterparty could be checked.
  • Technical observation recorded two successful behavioral runs with no external requests, no hidden forms, and no wallet-provider activity.

Summary Verdict

The website should be treated as an established-domain asset with an unverified operator and an unacceptable posture for sensitive interaction. The decisive concern is the convergence of confirmed external reputation contradictions with insufficient current identity and transaction context, notwithstanding the site’s otherwise limited and technically quiet presentation.

Infrastructure Integrity

The site resolves to a single Oracle-hosted address, with no CDN or WAF detected and no separate origin candidates identified. Oracle hosting and valid TLS provide basic service continuity and transport protection, but they are infrastructure characteristics only and do not offset the external reputation findings.

Closing Assessment

Restrict activity to passive observation unless independent counterparty, transfer, payment-protection, and contact-channel checks have been completed; credentials, payments, downloads, and other sensitive actions should not be undertaken on the basis of the page alone.

Written analysis generated 2026-08-18 by the TrustSniffer Analysis Engine from the evidence in this report.

What the analysis found

2 findings contributed to this verdict, raised by registration and ownership, analysis engine, behaviour in a sandbox, external reputation.

01 Governance Risk

  • The public registration record for this domain is incomplete.Registration and ownership rule:KF_WHOIS_INCOMPLETE

02 Sensitive Interaction Risk

  • The analysis matched a pattern TrustSniffer treats as a direct threat to a visitor.Analysis engine signal:direct_threat
  • A large share of what the page loaded came from other domains.Behaviour in a sandbox rule:BEHAV_EXTERNAL_RATIO_MODERATE
  • An external threat feed lists this domain: either Google Safe Browsing marked it malicious, or a significant number of malware engines flagged it.External reputation rule:EXT_BLACKLIST_CRITICAL

Identity verification

StatusUNVERIFIED
Identity score30/100
Identity verification confidence50%
  • No on-site identity signals detected

Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence.

What TrustSniffer observed

First-party facts recorded during the assessment of 10mais.com.br.

  • The request stayed on 10mais.com.br. It was not redirected to another domain. Clear
  • DNS for this domain is served by com.br, across 2 name servers. Noted
  • The registration is paid up to 2026-11-11. Noted
  • The earliest public archive of this site is from 2000-10-18. Clear
  • It is hosted on ORACLE-BMC-31898, from a server in US. Noted

Domain intelligence

RegistrarNot available
HostingORACLE-BMC-31898 - Oracle Corporation, US
CountryUS
Server IP162.241.203.11
Name serversns976.hostgator.com.br, ns977.hostgator.com.br
SSL issuerYR2
SSL expiry2026-10-25
Domain age26.79 years (continuous registration)
Domain expiry2026-11-11
Archive first seen2000-10-18
Archive snapshots49
ReputationVirusTotal: 4 flagged | AbuseIPDB: 0 reports | Google Safe Browsing: 0 matches

About this assessment

A trust score summarises the evidence TrustSniffer could collect about 10mais.com.br at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.

TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.

Common questions about 10mais.com.br

Is 10mais.com.br a scam?

TrustSniffer's assessment of 10mais.com.br found strong scam indicators. It scored 0 out of 100 on 2026-08-18, which is the critical-risk band. The specific signals are listed in the evidence above.

Is 10mais.com.br safe to use?

This assessment found strong scam indicators. Do not pay, sign in, or share personal details with this site.

What is the trust score of 10mais.com.br?

10mais.com.br scored 0 out of 100 on 2026-08-18, which places it in the critical-risk band. The score is built from the domain's age and registration history, its hosting and certificate, the content of the site itself, and third-party reputation data. There is no human rating and no user review in it.

Download this report as PDF Free, no account needed. Create one to keep a history of the sites you check.
By AminRez, Founder & Lead Security Researcher, TrustSniffer
Produced by the TrustSniffer Analysis Engine · assessed 2026-08-18 · how we assess · report a mistake