---
title: "Is 1r2.pl a Scam? Trust Score 0/100"
source: TrustSniffer
type: Website trust & fraud report
subject: "1r2.pl"
verdict: "Critical Risk"
title: "Is 1r2.pl a Scam? Trust Score 0/100"
trust_score: 0
classification_confidence: 70
canonical_url: https://trustsniffer.com/report/1r2.pl
assessed: 2026-08-18
---

# Is 1r2.pl a scam? TrustSniffer's high-risk assessment: 0/100

## Verdict


**Verdict: Critical Risk, trust score 0/100.** 1r2.pl shows high-risk / scam indicators.

This assessment found strong scam indicators. Do not pay, sign in, or share personal details with this site.

Labels: Sensitive Interaction Risk, Governance Risk

Assessed 2026-08-18 by automated analysis. Classification confidence 70%.

| Field | Value |
| --- | --- |
| What this site appears to be | Polish-language informational site focused on local technical and administrative services (water permits, engineering, promotional products). Content is editorial, aimed at advising on permit applications and promoting service offerings. Cookie consent UI is present. |

## Evidence status and limitations


Evidence completeness: UNKNOWN

- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.

## At a glance

The checks that decide most of this verdict.

| Check | Result | Status |
| --- | --- | --- |
| Malware engines | 12 flagged it (VirusTotal) | Risk |
| Google Safe Browsing | Not listed (Google) | Clear |
| Abuse reports on the host | 0 reports (AbuseIPDB; shared hosting inflates this count) | Noted |
| Domain age | 1.1 years old (Registered history) | Clear |
| Web archive | Archived since 2012 (24 snapshots) | Clear |
| Certificate | Encrypted connection (Issued by YE1) | Noted |

## The page as captured


![Screenshot of the 1r2.pl homepage captured during the TrustSniffer assessment](https://trustsniffer.com/outputs/1r2.pl/screenshots/first.png)

_What 1r2.pl served when TrustSniffer captured it on 2026-08-18. The page may look different now._

## Key findings


- Automated classification: Sensitive Interaction Risk.
- Domain age: 1 to 3 years (registration continuity).
- Public web-archive history exists since 2012.
- At least one reputation service TrustSniffer consulted had flagged this domain at assessment time.

## Full analysis


### Security Alert

Sophos flagged this site in external intelligence checks, indicating elevated compromise/scam exposure that requires immediate caution.

The website is a Polish-language informational portal presenting articles and service-oriented content concerning water permits, engineering activities, electromagnetic measurements, promotional products, and related local business services; its apparent model is lead generation, service promotion, or referral-based advertising rather than direct financial or account-based interaction.


### Scam/Impersonation Risk

No brand impersonation, phishing form, or conflicting legal identity was observed in the supplied page evidence. However, this benign presentation is materially contradicted by external threat intelligence: the domain is blacklisted, multiple detections classify it as malicious, and browser analysis identified suspicious external network activity, non-whitelisted POST requests, and a final-destination mismatch. The available evidence therefore supports a clearly cautionary posture for credentials, financial activity, downloads, or other sensitive interaction. Historical captures show no detected repurposing pattern, but historical continuity does not neutralize the current reputation findings. Evidence:

- The homepage presents Polish-language informational and local-service material and contains a cookie-consent form rather than a login or password form.
- External reputation telemetry recorded 12 malicious detections, 1 suspicious detection, and a confirmed blacklist.
- The domain registration record shows creation on 2025-07-07 and an age of approximately 1.11 years.
- Web-archive records contain 24 snapshots spanning 2012–2026, covering 15 tracked years, with no detected semantic repurposing.

### Regulatory Verification Notes

The site's apparent service model is not itself evidence of fraud, and the page analysis identified no content-level red flags. Nevertheless, the real-world operator remains unverified, governance and ownership disclosure are unclear, and no licensing authority or license number is claimed in the available business profile. Any regulated or professionally restricted service represented by the site should therefore be treated as unverified until the responsible legal entity and applicable authorization are independently established. Evidence:

- The available site materials do not independently connect the portal to a verified legal entity or responsible person.
- No license authority or license number is recorded in the site's business information.
- Hosting is recorded on AS16276 through OVH - OVH SAS, FR.
- The transport certificate is DV, issued by YE1, and valid to 2026-11-06T08:08:48+00:00.

### What to Verify Next

Before any engagement, the responsible legal entity should be confirmed through the relevant Polish corporate and professional registries, with particular attention to whether the advertised permit, engineering, or measurement services require authorization. Any contact or payment details should be validated through an independently sourced route, and sensitive interaction should remain suspended unless the external threat findings are resolved and the operator's responsibility for the domain is documented. Evidence:

- The site's service-led presentation does not by itself establish who is legally responsible for delivery or contracting.
- The absence of a stated licensing authority or number makes registry confirmation the specific next verification step.
- The observed browser session did not expose a password form, but this does not validate any future request for credentials or payment information.

### Summary Verdict

The overall posture is **critical risk** for sensitive interaction. The site's informational appearance is insufficient to overcome the convergent external threat and provenance concerns, and its real-world operator cannot presently be treated as independently verified.


### Infrastructure Integrity

A CDN/WAF layer is present, with observed edge infrastructure and potential origin candidates. This provides a limited protective control against some direct exposure risks, but infrastructure protection is not evidence that the site's content, operator, or external reputation is legitimate.


### Closing Assessment

Credentials, financial transactions, downloads, and reliance on the site's service representations should be withheld unless independent identity, authorization, and threat-status checks produce satisfactory results.


_Written analysis generated 2026-08-18 by the TrustSniffer Analysis Engine from the evidence in this report._

## What the analysis found

2 findings contributed to this verdict, raised by registration and ownership, analysis engine, behaviour in a sandbox, external reputation.

### 01 Governance Risk
- The public registration record for this domain is incomplete. (Registration and ownership `rule:KF_WHOIS_INCOMPLETE`)

### 02 Sensitive Interaction Risk
- The analysis matched a pattern TrustSniffer treats as a direct threat to a visitor. (Analysis engine `signal:direct_threat`)
- The page sent data to a destination TrustSniffer does not recognise. (Behaviour in a sandbox `rule:BEHAV_NONWHITELISTED_POSTS`)
- A large share of what the page loaded came from other domains. (Behaviour in a sandbox `rule:BEHAV_EXTERNAL_RATIO_MODERATE`)
- An external threat feed lists this domain: either Google Safe Browsing marked it malicious, or a significant number of malware engines flagged it. (External reputation `rule:EXT_BLACKLIST_CRITICAL`)

## Identity verification


| Field | Value |
| --- | --- |
| Status | UNVERIFIED |
| Identity score | 30/100 |
| Identity verification confidence | 50% |

- No on-site identity signals detected

_Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence._

## What TrustSniffer observed

First-party facts recorded during the assessment of 1r2.pl.

- The request stayed on 1r2.pl. It was not redirected to another domain. (Clear)
- Registration is published under OVH SAS. (Clear)
- DNS for this domain is served by ovh.net, across 2 name servers. (Noted)
- The registration is paid up to 2027-07-07. (Noted)
- The earliest public archive of this site is from 2012-04-08. (Clear)
- It is hosted on OVH, from a server in FR. (Noted)

## Domain intelligence


| Field | Value |
| --- | --- |
| Registrar | OVH SAS |
| Hosting | OVH - OVH SAS, FR |
| Country | FR |
| Server IP | 2001:41d0:301:9::21 |
| Name servers | dns100.ovh.net, ns100.ovh.net |
| SSL issuer | YE1 |
| SSL expiry | 2026-11-06 |
| Domain age | 1.11 years (continuous registration) |
| Domain expiry | 2027-07-07 |
| Archive first seen | 2012-04-08 |
| Archive snapshots | 24 |
| Reputation | VirusTotal: 12 flagged \| AbuseIPDB: 0 reports \| Google Safe Browsing: 0 matches |

## About this assessment


A trust score summarises the evidence TrustSniffer could collect about 1r2.pl at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.

TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.

## Related on TrustSniffer
- [prestigo.pl risk report](https://trustsniffer.com/report/prestigo.pl) (Critical Risk, 0/100)
- [lumiprojekt.pl risk report](https://trustsniffer.com/report/lumiprojekt.pl) (Critical Risk, 0/100)
- [2137.pl risk report](https://trustsniffer.com/report/2137.pl) (Critical Risk, 0/100)
- [velazquezinc.com risk report](https://trustsniffer.com/report/velazquezinc.com) (Critical Risk, 5/100)
- [bet9999.bet risk report](https://trustsniffer.com/report/bet9999.bet) (Critical Risk, 7/100)
- [bet63xxx.com risk report](https://trustsniffer.com/report/bet63xxx.com) (Critical Risk, 0/100)
- [d-a-g.ru risk report](https://trustsniffer.com/report/d-a-g.ru) (Critical Risk, 0/100)
- [bztlxx.com risk report](https://trustsniffer.com/report/bztlxx.com) (Critical Risk, 5/100)
- [crzxjx.com risk report](https://trustsniffer.com/report/crzxjx.com) (Critical Risk, 5/100)
- [gemini-project.eu risk report](https://trustsniffer.com/report/gemini-project.eu) (Critical Risk, 5/100)
- [Every website and wallet TrustSniffer has assessed](https://trustsniffer.com/directory)
- [Other domains assessed as high-risk or phishing](https://trustsniffer.com/directory/phishing-domains)
- [Check another website](https://trustsniffer.com/web-intelligence)
- [Check a crypto wallet address](https://trustsniffer.com/on-chain-risk)
- [The TrustSniffer Risk Index](https://trustsniffer.com/stats)

## Guides
- [Stablecoin Freezes, Sep 22, 2026: 60 Wallets](https://trustsniffer.com/blog/stablecoin-freeze-report-2026-09-22)
- [The Malware Hidden Inside Minecraft Mods](https://trustsniffer.com/blog/minecraft-mod-malware)
- [Stablecoin Freezes, Sep 29, 2026: 9 Wallets](https://trustsniffer.com/blog/stablecoin-freeze-report-2026-09-29)

---
*Source: [TrustSniffer](https://trustsniffer.com/report/1r2.pl) — independent automated trust & fraud analysis. Cite as https://trustsniffer.com/report/1r2.pl · assessed 2026-08-18.*
