Verdict
376797.com shows high-risk / scam indicators.
This assessment found strong scam indicators. Do not pay, sign in, or share personal details with this site.
| What this site appears to be | Chinese education portal with repeated site title and numerous articles covering exam channels (college entrance exam, middle school exams), study guides, course comparisons, certifications, and school rankings. No visible login, payment, or investment flows on the captured page. |
|---|
Evidence status and limitations
Evidence completeness: UNKNOWN
- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.
At a glance
The checks that decide most of this verdict.
| Malware engines | 11 flagged itVirusTotal | Risk |
|---|---|---|
| Google Safe Browsing | Not listedGoogle | Clear |
| Abuse reports on the host | 0 reportsAbuseIPDB; shared hosting inflates this count | Noted |
| Domain age | 1.6 years oldRegistered history | Clear |
| Web archive | Archived since 2018Public history exists | Clear |
| Certificate | Encrypted connectionIssued by WE1 | Noted |
The page as captured
Key findings
- Automated classification: Sensitive Interaction Risk.
- Domain age: 1 to 3 years (registration continuity).
- Public web-archive history exists since 2018.
- At least one reputation service TrustSniffer consulted had flagged this domain at assessment time.
Full analysis
Security Alert
Fortinet, Kaspersky, Sophos flagged this site in external intelligence checks, indicating elevated compromise/scam exposure that requires immediate caution.
The website is a Chinese-language education and examination-information portal presenting study resources, examination channels, school rankings, course comparisons, certification-related articles, and educational news. Its apparent model is content aggregation, potentially supported by advertising, affiliate activity, or syndication, although explicit monetization details are not visible on the captured homepage.
Scam/Impersonation Risk
No identity contradiction or page-level brand impersonation was observed in the captured content, and the homepage did not present a login, payment, or investment flow. However, external security telemetry recorded 11 malicious detections, including detections associated with Fortinet, Kaspersky, and Sophos, and the domain is confirmed as blacklisted by multiple external blacklist sources. This convergence overrides the relatively benign educational presentation and creates a material risk for sensitive interaction, including credential submission, account use, or financial activity. The site should therefore be treated as a critical trust risk rather than as an ordinary informational portal.
- External reputation telemetry recorded 11 malicious detections, with Fortinet, Kaspersky, and Sophos among the flagged vendors.
- The domain was recorded as blacklisted by two external blacklist sources.
- The homepage capture contained educational articles and no visible login, payment, or investment flow.
- Domain registration record: 2025-01-15; age 1.59 years; registrar Spaceship, Inc.
Regulatory Verification Notes
The captured site does not establish a verified real-world operator, legal entity, licensing authority, or registration number. Its educational publishing activity does not by itself demonstrate accreditation, regulatory authorization, or institutional affiliation; these omissions are verification gaps rather than independent proof of fraud. The available technical signals show functioning transport security and identifiable hosting, but those controls do not validate the operator or offset the external reputation findings.
- The homepage contained no visible license claim, license number, or named regulatory authority.
- Hosted on AS13335 (CLOUDFLARENET - Cloudflare, Inc., US).
- TLS certificate issued by WE1 with DV validation, valid to 2026-10-11.
- WHOIS registration lists Spaceship, Inc. as registrar, with creation date 2025-01-15 and expiration date 2027-01-15.
What to Verify Next
Before any sensitive interaction, an organization should independently establish the responsible legal entity and confirm any claimed educational, examination, or training affiliation through the relevant official institution or registry. Contact channels should be validated through an independently sourced route, and security personnel should review the destination and network behavior before permitting credentials, payment information, downloads, or account access. Pending that validation, use should remain limited to passive viewing.
- Behavioral capture recorded 4 external XHR requests and 4 external POST requests.
- Of those requests, 2 XHR requests and 2 POST requests were classified as non-whitelisted.
- No hidden forms were detected, and the behavioral capture recorded 0 password submissions to external forms.
- Wallet-connect, wallet-sensitive, and wallet-drainer executions were each recorded as 0.
Summary Verdict
The site presents a superficially ordinary educational-content profile but does not achieve a trustworthy operational posture. The confirmed external threat and blacklist signals, combined with unverified operator identity and unclear disclosure, support a critical trust assessment for sensitive use.
Infrastructure Integrity
Cloudflare provides the site’s CDN/WAF protection, and all observed addresses were CDN edge infrastructure rather than an identifiable origin server. This reduces direct exposure of the hosting environment and is a mitigating technical control only; it does not establish legitimacy or neutralize the reputation risk.
- Observed IPv4 edge addresses: 104.21.8.156 and 172.67.188.142.
- Observed IPv6 edge addresses: 2606:4700:3030::ac43:bc8e and 2606:4700:3031::6815:89c.
- All 4 observed IP addresses were associated with AS13335; 0 origin candidates were identified.
Closing Assessment
Sensitive interaction should be withheld unless independent operator validation and a focused security review produce satisfactory results; passive viewing is the proportionate interim posture.
Written analysis generated 2026-08-20 by the TrustSniffer Analysis Engine from the evidence in this report.
What the analysis found
2 findings contributed to this verdict, raised by registration and ownership, analysis engine, behaviour in a sandbox, external reputation.
01 Governance Risk
- The public registration record for this domain is incomplete.Registration and ownership
rule:KF_WHOIS_INCOMPLETE
02 Sensitive Interaction Risk
- The analysis matched a pattern TrustSniffer treats as a direct threat to a visitor.Analysis engine
signal:direct_threat - Most of what the page loaded came from other domains rather than from this one.Behaviour in a sandbox
rule:BEHAV_EXTERNAL_RATIO_HIGH - The page sent data to a destination TrustSniffer does not recognise.Behaviour in a sandbox
rule:BEHAV_NONWHITELISTED_POSTS - An external threat feed lists this domain: either Google Safe Browsing marked it malicious, or a significant number of malware engines flagged it.External reputation
rule:EXT_BLACKLIST_CRITICAL
Identity verification
| Status | UNVERIFIED |
|---|---|
| Identity score | 30/100 |
| Identity verification confidence | 50% |
- No on-site identity signals detected
Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence.
What TrustSniffer observed
First-party facts recorded during the assessment of 376797.com.
- The request stayed on 376797.com. It was not redirected to another domain. Clear
- Registration is published under Spaceship, Inc.. Clear
- DNS for this domain is served by cloudflare.com, across 2 name servers. Noted
- The registration is paid up to 2027-01-15. Noted
- The earliest public archive of this site is from 2018-08-06. Clear
- It is hosted on CLOUDFLARENET, from a server in US. Noted
Domain intelligence
| Registrar | Spaceship, Inc. |
|---|---|
| Hosting | CLOUDFLARENET - Cloudflare, Inc., US |
| Country | US |
| Server IP | 2606:4700:3031::6815:89c |
| Name servers | ANNA.NS.CLOUDFLARE.COM, TOM.NS.CLOUDFLARE.COM |
| SSL issuer | WE1 |
| SSL expiry | 2026-10-11 |
| Domain age | 1.59 years (continuous registration) |
| Domain expiry | 2027-01-15 |
| Archive first seen | 2018-08-06 |
| Archive snapshots | Not counted (archive lookup incomplete) |
| Reputation | VirusTotal: 11 flagged | AbuseIPDB: 0 reports | Google Safe Browsing: 0 matches |
About this assessment
A trust score summarises the evidence TrustSniffer could collect about 376797.com at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.
TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.