Verdict
1tg.us shows high-risk / scam indicators.
This assessment found strong scam indicators. Do not pay, sign in, or share personal details with this site.
| What this site appears to be | A standard Bluehost default/parked page indicating the site is under construction. Contains links to cPanel, support resources and Bluehost branding. No forms or payment flows present. |
|---|
Evidence status and limitations
Evidence completeness: UNKNOWN
- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.
At a glance
The checks that decide most of this verdict.
| Malware engines | 9 flagged itVirusTotal | Risk |
|---|---|---|
| Google Safe Browsing | Not listedGoogle | Clear |
| Abuse reports on the host | 0% confidenceAbuseIPDB, 1 report; shared hosting inflates reports | Clear |
| Domain age | 19 years oldRegistered history | Clear |
| Web archive | Archived since 2013243 snapshots | Clear |
| Certificate | Encrypted connectionIssued by YR1 | Noted |
The page as captured
Key findings
- Automated classification: Sensitive Interaction Risk.
- Domain age: more than 10 years (registration continuity).
- Public web-archive history exists since 2013.
- At least one reputation service TrustSniffer consulted had flagged this domain at assessment time.
Full analysis
Security Alert
Fortinet, Sophos flagged this site in external intelligence checks, indicating elevated compromise/scam exposure that requires immediate caution.
The website is a parked, under-construction hosting page presenting Bluehost-branded default content, including links to cPanel, support resources, domain management, tutorials, and a forum; its apparent purpose is domain parking or temporary hosting rather than an active commercial service.
Scam/Impersonation Risk
The domain carries a critical sensitive-interaction risk because external reputation systems recorded malicious detections and a confirmed blacklist status. This evidence outweighs the benign appearance of the visible page. A separate abuse report concerns the shared provider infrastructure rather than the domain specifically; it has zero confidence and is discounted for that reason. The homepage itself is a generic Bluehost default page hosted on a different assessed domain, creating a provenance concern that requires independent confirmation, although no login form, payment flow, or sensitive form was visible. No confirmed legal-entity conflict or active impersonation flow is established by the supplied page evidence.
- External reputation assessment recorded 9 malicious detections and 1 suspicious detection for the domain, with Tier-1 threat detections present.
- The domain is recorded as blacklisted by two external source categories.
- The homepage title is “Bluehost.com | Welcome,” while the assessed domain is 1tg.us; the page states that the site is temporary and under construction.
Regulatory Verification Notes
The current page does not disclose an operating business, regulated activity, license, registration number, or substantive terms of service. That is a transparency and verification gap rather than standalone proof of misconduct. The registration record identifies TOM GALLOVICH and the organization “tagart,” but the available evidence does not independently verify that this registrant operates the website. No broker-reputation match was identified in the supplied third-party context, but that result is not a licensing or regulatory determination.
- The domain was registered on 2007-08-26 and is 18.99 years old; the listed registrar is Fastdomains.
- Archive records contain 243 snapshots spanning 2013–2026, covering 14 tracked years.
- The registration record lists TOM GALLOVICH as owner and “tagart” as organization.
- The current homepage provides hosting-placeholder content but no license, registration number, or operating-entity disclosure.
What to Verify Next
Before any sensitive interaction, an organization should independently confirm whether the domain is intentionally associated with Bluehost or with the named registrant, using an established offline or independently sourced contact route. Any claimed regulated or financial purpose should be checked directly against the relevant jurisdictional registry. The domain should not be used for login, credential submission, payments, or other financial activity unless its ownership and purpose have been independently resolved.
- Behavioral testing completed 2 successful runs and recorded 10 external XHR requests and 6 external POST requests.
- Testing recorded 14 console errors and a maximum post-interaction DOM difference of 117 elements.
- No hidden forms, password-external forms, wallet connections, or wallet-drainer activity were detected during the observed runs.
Summary Verdict
The overall posture is critical and the available evidence does not support treating this domain as trustworthy for sensitive interaction. Its benign parked-page presentation is insufficient to overcome the confirmed external threat and blacklist indicators. Identity verification remains unresolved.
Infrastructure Integrity
The site resolves through Oracle Corporation infrastructure in the United States, specifically AS31898, with no CDN or WAF deployment detected and no separate edge or origin candidates identified in the infrastructure assessment. The hosting arrangement is a neutral technical fact and does not establish legitimacy; it provides no identified protective mitigation against the external reputation concerns.
Closing Assessment
Prospective users and institutions should refrain from sensitive interaction with the domain until its purpose, ownership, and any intended relationship to the displayed hosting brand are independently confirmed.
Written analysis generated 2026-08-18 by the TrustSniffer Analysis Engine from the evidence in this report.
What the analysis found
1 finding contributed to this verdict, raised by analysis engine, behaviour in a sandbox, external reputation.
01 Sensitive Interaction Risk
- The analysis matched a pattern TrustSniffer treats as a direct threat to a visitor.Analysis engine
signal:direct_threat - Most of what the page loaded came from other domains rather than from this one.Behaviour in a sandbox
rule:BEHAV_EXTERNAL_RATIO_HIGH - An external threat feed lists this domain: either Google Safe Browsing marked it malicious, or a significant number of malware engines flagged it.External reputation
rule:EXT_BLACKLIST_CRITICAL
Signals weighed against the site
- AbuseIPDB: 1 report on hosting IP 162.241.218.70 (Unified Layer, Content Delivery Network), 0% confidence. The reports are attributed to shared infrastructure, not specifically to this website.
Identity verification
| Status | UNVERIFIED |
|---|---|
| Identity score | 30/100 |
| Identity verification confidence | 50% |
- No on-site identity signals detected
Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence.
What TrustSniffer observed
First-party facts recorded during the assessment of 1tg.us.
- The request stayed on 1tg.us. It was not redirected to another domain. Clear
- Registration is published under Fastdomains. Clear
- DNS for this domain is served by bluehost.com, across 2 name servers. Noted
- The registration is paid up to 2027-08-25. Noted
- The earliest public archive of this site is from 2013-07-21. Clear
- It is hosted on ORACLE-BMC-31898, from a server in US. Noted
Domain intelligence
| Registrar | Fastdomains |
|---|---|
| Hosting | ORACLE-BMC-31898 - Oracle Corporation, US |
| Country | US |
| Server IP | 162.241.218.70 |
| Name servers | ns2.bluehost.com, ns1.bluehost.com |
| SSL issuer | YR1 |
| SSL expiry | 2026-11-02 |
| Domain age | 18.99 years (continuous registration) |
| Domain expiry | 2027-08-25 |
| Archive first seen | 2013-07-21 |
| Archive snapshots | 243 |
| Reputation | VirusTotal: 9 flagged | AbuseIPDB: 0% confidence, 1 report | Google Safe Browsing: 0 matches |
About this assessment
A trust score summarises the evidence TrustSniffer could collect about 1tg.us at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.
TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.