---
title: "Is 1226project.com a Scam? Trust Score 0/100"
source: TrustSniffer
type: Website trust & fraud report
subject: "1226project.com"
verdict: "Critical Risk"
title: "Is 1226project.com a Scam? Trust Score 0/100"
trust_score: 0
classification_confidence: 75
canonical_url: https://trustsniffer.com/report/1226project.com
assessed: 2026-08-18
---

# Is 1226project.com a scam? TrustSniffer's high-risk assessment: 0/100

## Verdict


**Verdict: Critical Risk, trust score 0/100.** 1226project.com shows high-risk / scam indicators.

This assessment found strong scam indicators. Do not pay, sign in, or share personal details with this site.

Labels: Sensitive Interaction Risk, Governance Risk

Assessed 2026-08-18 by automated analysis. Classification confidence 75%.

| Field | Value |
| --- | --- |
| What this site appears to be | Corporate website for XII.XXVI Project (1226 Project), an investment and consulting firm offering equity participation, real estate and company investments, with contact details and a simple contact form. |

## Evidence status and limitations


Evidence completeness: UNKNOWN

- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.

## At a glance

The checks that decide most of this verdict.

| Check | Result | Status |
| --- | --- | --- |
| Malware engines | 14 flagged it (VirusTotal) | Risk |
| Google Safe Browsing | Not listed (Google) | Clear |
| Abuse reports on the host | 11% confidence (AbuseIPDB, 23 reports; shared hosting inflates reports) | Clear |
| Domain age | 8.5 years old (Registered history) | Clear |
| Web archive | Archived since 2018 (394 snapshots) | Clear |
| Certificate | Encrypted connection (Issued by YE2) | Noted |

## The page as captured


![Screenshot of the 1226project.com homepage captured during the TrustSniffer assessment](https://trustsniffer.com/outputs/1226project.com/screenshots/first.png)

_What 1226project.com served when TrustSniffer captured it on 2026-08-18. The page may look different now._

## Key findings


- Automated classification: Sensitive Interaction Risk.
- Domain age: 3 to 10 years (registration continuity).
- Public web-archive history exists since 2018.
- At least one reputation service TrustSniffer consulted had flagged this domain at assessment time.

## Full analysis


### Security Alert

Sophos flagged this site in external intelligence checks, indicating elevated compromise/scam exposure that requires immediate caution.

XII.XXVI Project, also presented as 1226 Project, is a corporate investment and consulting website offering equity participation, real-estate and company investments, commercial development, and advisory services. Its apparent business model is to generate revenue through investments, participation in portfolio activities, and consulting engagements.


### Scam/Impersonation Risk

The site presents no apparent brand impersonation, conflicting legal identities, credential-harvesting form, or phishing-style login flow in the reviewed pages. However, this does not offset the decisive external risk signals: the domain is blacklisted by multiple external sources, with multiple malicious detections including a Tier-1 detection from Sophos, and the observed browser behavior included suspicious inline scripts and suspicious network activity. The site’s transport and content continuity are therefore insufficient to establish safety for sensitive interaction. Separate reports concerning the observed IP are attributed to shared infrastructure, so they do not uniquely identify this website, but they remain adverse contextual evidence. No confirmed identity contradiction was observed in the supplied page content.


Evidence:
- The homepage presents a corporate investment and consulting service, while behavioral analysis recorded 2 suspicious inline scripts and corrected suspicious network activity.
- External reputation assessment recorded 14 malicious detections and 1 suspicious detection; blacklist status was confirmed by the evaluated sources, including a Sophos detection.
- The observed IP had 23 abuse reports, attributed to shared OVH infrastructure rather than uniquely to the website.
- Domain registration evidence records creation on 2018-02-18, with an age of approximately 8.5 years; archive evidence records 394 snapshots spanning 2018–2026 across 9 years, indicating continuity but not resolving the current threat detections.

### Regulatory Verification Notes

The website describes XII.XXVI Project as an investment company focused on economic development and states that it invests in real estate and companies while offering consulting services. Its listed activity areas include finance, vehicles, furniture, companies, stores, commercial development, purchase and sale of goods and services, and commercial and competitive strategy; it also claims 25 years of trading experience. No investment license, licensing authority, or registration number is claimed in the supplied content, leaving the legal and regulatory basis for offering investment-related services unclear. The available evidence is insufficient to independently verify the operator’s real-world identity, and the site’s investment claims should not be treated as evidence of authorization.


Evidence:
- The homepage states that the business provides direct investment through equity participation, vehicle purchases, and real-estate investment, alongside consulting services.
- The homepage identifies the entity as “XII.XXVI Project” and describes investment in real estate and companies, but no license number or licensing authority is provided.
- The site’s hosting infrastructure is served from AS16276, OVH - OVH SAS, France.
- The site’s TLS certificate is issued by YE2 at DV validation level and is valid to 2026-10-05.

### What to Verify Next

Before any engagement, an independent check should establish the legal entity behind XII.XXVI Project and confirm whether the relevant jurisdiction requires authorization for its investment activities. Any claimed authorization should be matched against the appropriate financial-services or corporate registry rather than relying on statements on the website. Contact details should be validated through an independently obtained or offline-confirmed channel, and no funds, identity documents, credentials, or sensitive financial information should be submitted while those checks remain unresolved.


Evidence:
- The homepage provides a contact route through a single contact form and does not present a login form or sensitive credential-collection form.
- The website’s stated services involve investment and consulting activity, making confirmation of the applicable authorization regime a necessary pre-engagement step.
- The supplied identity assessment records the operator’s real-world identity as unverified.

### Summary Verdict

The website should be treated as a **critical trust risk** for sensitive interaction. Although its content is consistent with a corporate investment presentation and its domain has demonstrated historical continuity, the confirmed blacklist and malicious-detection signals make the available evidence inadequate to support financial engagement or credential use.


### Infrastructure Integrity

The site is protected by a CDN/WAF layer operated through OVH infrastructure, with the observed edge address hosted on AS16276; the origin server was not observable in this analysis. This provides a mitigating layer against direct exposure but is an infrastructure control only and does not establish the website’s legitimacy.


### Closing Assessment

The appropriate posture is to keep activity strictly non-sensitive until independent identity, authorization, and contact-channel checks produce satisfactory results; financial transfers, credential submission, and disclosure of sensitive information should remain suspended in the interim.


_Written analysis generated 2026-08-18 by the TrustSniffer Analysis Engine from the evidence in this report._

## What the analysis found

2 findings contributed to this verdict, raised by registration and ownership, analysis engine, behaviour in a sandbox, external reputation.

### 01 Governance Risk
- Registration details are held behind a privacy service, so no operator is named publicly. This is common and legal, and it also means there is nobody to check. (Registration and ownership `rule:KF_WHOIS_PRIVATE`)
- The registration record withholds contact details for the operator. (Registration and ownership `rule:KF_WHOIS_HIDDEN`)

### 02 Sensitive Interaction Risk
- The analysis matched a pattern TrustSniffer treats as a direct threat to a visitor. (Analysis engine `signal:direct_threat`)
- The page carried inline scripts written in a style TrustSniffer treats as suspicious. (Behaviour in a sandbox `rule:BEHAV_SUSPICIOUS_INLINE_SCRIPTS`)
- An external threat feed lists this domain: either Google Safe Browsing marked it malicious, or a significant number of malware engines flagged it. (External reputation `rule:EXT_BLACKLIST_CRITICAL`)

### Signals weighed against the site

- AbuseIPDB: 23 reports on hosting IP 87.98.154.146 (OVH SAS, Content Delivery Network), 11% confidence. The reports are attributed to shared infrastructure, not specifically to this website.

## Identity verification


| Field | Value |
| --- | --- |
| Status | UNVERIFIED |
| Identity score | 30/100 |
| Identity verification confidence | 25% |

- No on-site identity signals detected

_Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence._

## What TrustSniffer observed

First-party facts recorded during the assessment of 1226project.com.

- The request stayed on 1226project.com. It was not redirected to another domain. (Clear)
- Registration is published under OVH, SAS. (Clear)
- DNS for this domain is served by ovh.net, across 2 name servers. (Noted)
- The registration is paid up to 2027-02-18. (Noted)
- The earliest public archive of this site is from 2018-03-24. (Clear)
- It is hosted on OVH, from a server in FR. (Noted)

## Domain intelligence


| Field | Value |
| --- | --- |
| Registrar | OVH, SAS |
| Hosting | OVH - OVH SAS, FR |
| Country | FR |
| Server IP | 87.98.154.146 |
| Name servers | DNS18.OVH.NET, NS18.OVH.NET |
| SSL issuer | YE2 |
| SSL expiry | 2026-10-05 |
| Domain age | 8.50 years (continuous registration) |
| Domain expiry | 2027-02-18 |
| Archive first seen | 2018-03-24 |
| Archive snapshots | 394 |
| Reputation | VirusTotal: 14 flagged \| AbuseIPDB: 11% confidence, 23 reports \| Google Safe Browsing: 0 matches |

## About this assessment


A trust score summarises the evidence TrustSniffer could collect about 1226project.com at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.

TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.

## Related on TrustSniffer
- [printlogz.com risk report](https://trustsniffer.com/report/printlogz.com) (Critical Risk, 0/100)
- [activate-coinbase.com risk report](https://trustsniffer.com/report/activate-coinbase.com) (Critical Risk, 0/100)
- [exark.com risk report](https://trustsniffer.com/report/exark.com) (Critical Risk, 0/100)
- [riccbieber.com risk report](https://trustsniffer.com/report/riccbieber.com) (Critical Risk, 0/100)
- [kimzeycasing.com risk report](https://trustsniffer.com/report/kimzeycasing.com) (Critical Risk, 0/100)
- [photowalkingtoursbarcelona.com risk report](https://trustsniffer.com/report/photowalkingtoursbarcelona.com) (Critical Risk, 0/100)
- [bernardnainggolan.com risk report](https://trustsniffer.com/report/bernardnainggolan.com) (Critical Risk, 0/100)
- [coinpot.co risk report](https://trustsniffer.com/report/coinpot.co) (Critical Risk, 0/100)
- [gma-crypto.com risk report](https://trustsniffer.com/report/gma-crypto.com) (Critical Risk, 0/100)
- [elizabethsembroidery.co.uk risk report](https://trustsniffer.com/report/elizabethsembroidery.co.uk) (Critical Risk, 0/100)
- [Every website and wallet TrustSniffer has assessed](https://trustsniffer.com/directory)
- [Other domains assessed as high-risk or phishing](https://trustsniffer.com/directory/phishing-domains)
- [Check another website](https://trustsniffer.com/web-intelligence)
- [Check a crypto wallet address](https://trustsniffer.com/on-chain-risk)
- [The TrustSniffer Risk Index](https://trustsniffer.com/stats)

## Guides
- [Script Droppers: How This Download Scam Works](https://trustsniffer.com/blog/script-droppers-how-this-download-scam-works)
- [Stablecoin Freezes Sept 23, 2026: 11 Wallets](https://trustsniffer.com/blog/stablecoin-freeze-report-2026-09-23)
- [Stablecoin Freezes, Sep 22, 2026: 60 Wallets](https://trustsniffer.com/blog/stablecoin-freeze-report-2026-09-22)

---
*Source: [TrustSniffer](https://trustsniffer.com/report/1226project.com) — independent automated trust & fraud analysis. Cite as https://trustsniffer.com/report/1226project.com · assessed 2026-08-18.*
