---
title: "Is 2dr.eu a Scam? Trust Score 0/100"
source: TrustSniffer
type: Website trust & fraud report
subject: "2dr.eu"
verdict: "Critical Risk"
title: "Is 2dr.eu a Scam? Trust Score 0/100"
trust_score: 0
classification_confidence: 70
canonical_url: https://trustsniffer.com/report/2dr.eu
assessed: 2026-08-18
---

# Is 2dr.eu a scam? TrustSniffer's high-risk assessment: 0/100

## Verdict


**Verdict: Critical Risk, trust score 0/100.** 2dr.eu shows high-risk / scam indicators.

This assessment found strong scam indicators. Do not pay, sign in, or share personal details with this site.

Labels: Sensitive Interaction Risk, Governance Risk

Assessed 2026-08-18 by automated analysis. Classification confidence 70%.

| Field | Value |
| --- | --- |
| What this site appears to be | A URL-shortening and 2D barcode linking service offering shortlinks, analytics, hosted webpages and document hosting. The page includes examples of shortened links, a login form (email/password), and pricing guidance (charge per GB for hosting/analytics). |

## Evidence status and limitations


Evidence completeness: UNKNOWN

- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.

## At a glance

The checks that decide most of this verdict.

| Check | Result | Status |
| --- | --- | --- |
| Malware engines | 4 flagged it (VirusTotal) | Risk |
| Google Safe Browsing | Not listed (Google) | Clear |
| Abuse reports on the host | 0 reports (AbuseIPDB; shared hosting inflates this count) | Noted |
| Domain age | 15 years old (Registered history) | Clear |
| Web archive | Archived since 2011 (86 snapshots) | Clear |
| Certificate | Encrypted connection (Issued by YR2) | Noted |

## The page as captured


![Screenshot of the 2dr.eu homepage captured during the TrustSniffer assessment](https://trustsniffer.com/outputs/2dr.eu/screenshots/first.png)

_What 2dr.eu served when TrustSniffer captured it on 2026-08-18. The page may look different now._

## Key findings


- Automated classification: Sensitive Interaction Risk.
- Domain age: more than 10 years (registration continuity).
- Public web-archive history exists since 2011.
- At least one reputation service TrustSniffer consulted had flagged this domain at assessment time.

## Full analysis


### Security Alert

Kaspersky flagged this site in external intelligence checks, indicating elevated compromise/scam exposure that requires immediate caution.

The website is a URL-shortening and 2D barcode-linking service that presents link creation, click and scan analytics, hosted webpages, document hosting, link advertising, and account-based access. Its apparent business model is a paid SaaS service charging for hosting, data transfer, analytics, and related usage.


### Scam/Impersonation Risk

The site presents a coherent software-service proposition and the captured homepage showed no clear deceptive interface behavior, hidden forms, credential redirection, or brand-impersonation indicators. However, these benign page-level characteristics are outweighed by confirmed external reputation contradictions: the domain is recorded by multiple external sources as blacklisted, with malicious and suspicious detections present. No identity contradiction or brand impersonation was observed, but the external detections create a material risk for sensitive interaction, particularly because the site supports hosted content and user-created links that could be used to redirect visitors elsewhere.


Evidence:
- The homepage describes URL shortening, 2D barcode links, analytics, hosted webpages, document hosting, and link advertisements.
- External reputation checks recorded 4 malicious detections and 1 suspicious detection among 10 evaluated results, including a Tier-1 threat detection.
- The domain is approximately 15.09 years old, with 86 archive snapshots spanning 2011–2026 and 16 years tracked; historical continuity does not resolve the current reputation contradiction.

### Regulatory Verification Notes

The available site capture does not identify a licensing authority, registration number, or independently verified operating entity. That is a transparency and regulatory-verification gap rather than proof of fraud, but it is significant given the service’s account, hosting, analytics, and paid usage functions. The operator’s real-world identity remains unverified. The available third-party broker dataset produced no match, which provides limited neutral context and does not establish licensing or legitimacy.


Evidence:
- The homepage provides service and pricing descriptions but does not state a licensing authority or registration number.
- The site’s hosting was observed on AS21211, PENKI-AS - Penkiu kontinentu komunikaciju centras, Ltd., LT; WHOIS lists Blacknight Internet Solutions Ltd as registrar.
- The site uses a valid DV TLS certificate issued by YR2, valid to 2026-09-25T14:43:23+00:00.

### What to Verify Next

Independent verification should establish the operating entity, its jurisdiction, and the ownership of the service before any account or paid-service relationship is considered. Any applicable business registration or consumer-facing authorization should be checked directly with the relevant official registry rather than relying on statements displayed by the site. Contact channels should be validated through an independently sourced route, and any shortened or hosted destination should be inspected separately before access.


Evidence:
- The homepage contains an email-and-password login form for analytics access.
- The homepage offers account setup for document hosting and usage-based charges, including data-transfer pricing.
- The site provides user-created shortlinks and hosted pages, so the destination and content of each link require separate validation.

### Summary Verdict

The website has a **critical trust posture** driven by confirmed external reputation contradictions and unresolved operator-identity uncertainty. Its apparently conventional SaaS presentation and technically stable behavior do not offset the risk associated with the domain’s recorded malicious reputation.


### Infrastructure Integrity

CDN/WAF protection was observed, with CDN edge infrastructure and a potential origin candidate identified. This provides some mitigation against direct infrastructure exposure, but protective network architecture is not evidence that the operator or hosted content is legitimate.


Evidence:
- The infrastructure assessment identified a CDN/WAF layer, 2 CDN edge addresses, and 1 potential origin candidate.
- The resolved hosting environment is associated with PENKI-AS - Penkiu kontinentu komunikaciju centras, Ltd., LT.

### Closing Assessment

The appropriate posture is to avoid credential submission, paid engagement, and financial interaction until the operator and service purpose have been independently validated; any unavoidable inspection should remain limited to non-sensitive, read-only activity.


_Written analysis generated 2026-08-18 by the TrustSniffer Analysis Engine from the evidence in this report._

## What the analysis found

2 findings contributed to this verdict, raised by registration and ownership, analysis engine, external reputation.

### 01 Governance Risk
- The public registration record for this domain is incomplete. (Registration and ownership `rule:KF_WHOIS_INCOMPLETE`)

### 02 Sensitive Interaction Risk
- The analysis matched a pattern TrustSniffer treats as a direct threat to a visitor. (Analysis engine `signal:direct_threat`)
- An external threat feed lists this domain: either Google Safe Browsing marked it malicious, or a significant number of malware engines flagged it. (External reputation `rule:EXT_BLACKLIST_CRITICAL`)

## Identity verification


| Field | Value |
| --- | --- |
| Status | UNVERIFIED |
| Identity score | 30/100 |
| Identity verification confidence | 50% |

- No on-site identity signals detected

_Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence._

## What TrustSniffer observed

First-party facts recorded during the assessment of 2dr.eu.

- The request stayed on 2dr.eu. It was not redirected to another domain. (Clear)
- Registration is published under Blacknight Internet Solutions Ltd. (Clear)
- DNS for this domain is served by eu for more info.. (Noted)
- The earliest public archive of this site is from 2011-07-16. (Clear)
- It is hosted on PENKI-AS, from a server in LT. (Noted)

## Domain intelligence


| Field | Value |
| --- | --- |
| Registrar | Blacknight Internet Solutions Ltd |
| Hosting | PENKI-AS - Penkiu kontinentu komunikaciju centras, Ltd., LT |
| Country | LT |
| Server IP | 213.159.55.180 |
| Name servers | ns1.blacknight.com ns3.blacknight.com ns2.blacknight.com ns4.blacknight.com Please visit www.eurid.eu for more info. |
| SSL issuer | YR2 |
| SSL expiry | 2026-09-25 |
| Domain age | 15.09 years (continuous registration) |
| Domain expiry | Not available |
| Archive first seen | 2011-07-16 |
| Archive snapshots | 86 |
| Reputation | VirusTotal: 4 flagged \| AbuseIPDB: 0 reports \| Google Safe Browsing: 0 matches |

## About this assessment


A trust score summarises the evidence TrustSniffer could collect about 2dr.eu at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.

TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.

## Related on TrustSniffer
- [wiflix.eu risk report](https://trustsniffer.com/report/wiflix.eu) (Critical Risk, 0/100)
- [duckingproxy.eu risk report](https://trustsniffer.com/report/duckingproxy.eu) (Critical Risk, 0/100)
- [mojemieszkanie.eu risk report](https://trustsniffer.com/report/mojemieszkanie.eu) (Critical Risk, 0/100)
- [gemini-project.eu risk report](https://trustsniffer.com/report/gemini-project.eu) (Critical Risk, 5/100)
- [airwind.eu risk report](https://trustsniffer.com/report/airwind.eu) (Critical Risk, 0/100)
- [neje.club risk report](https://trustsniffer.com/report/neje.club) (Critical Risk, 0/100)
- [it-securegroup.com risk report](https://trustsniffer.com/report/it-securegroup.com) (Critical Risk, 0/100)
- [agroexportavocados.com risk report](https://trustsniffer.com/report/agroexportavocados.com) (Critical Risk, 0/100)
- [radiosouvenirs.be risk report](https://trustsniffer.com/report/radiosouvenirs.be) (Critical Risk, 0/100)
- [artella.uk risk report](https://trustsniffer.com/report/artella.uk) (Critical Risk, 0/100)
- [Every website and wallet TrustSniffer has assessed](https://trustsniffer.com/directory)
- [Other domains assessed as high-risk or phishing](https://trustsniffer.com/directory/phishing-domains)
- [Check another website](https://trustsniffer.com/web-intelligence)
- [Check a crypto wallet address](https://trustsniffer.com/on-chain-risk)
- [The TrustSniffer Risk Index](https://trustsniffer.com/stats)

## Guides
- [Stablecoin Freezes Sep 25, 2026: 8 Wallets](https://trustsniffer.com/blog/stablecoin-freeze-report-2026-09-25)
- [VietinBank Phishing: Spotting Domain Impersonation](https://trustsniffer.com/blog/vietinbank-phishing-domain-impersonation)
- [Stablecoin Freezes, Sep 24, 2026: 26 Wallets](https://trustsniffer.com/blog/stablecoin-freeze-report-2026-09-24)

---
*Source: [TrustSniffer](https://trustsniffer.com/report/2dr.eu) — independent automated trust & fraud analysis. Cite as https://trustsniffer.com/report/2dr.eu · assessed 2026-08-18.*
