Verdict
autofitness.ru shows high-risk / scam indicators.
This assessment found strong scam indicators. Do not pay, sign in, or share personal details with this site.
| What this site appears to be | Minimal landing page indicating the domain autofitness.ru is for sale via the Rucenter domain marketplace, showing a price and a buy link. No additional content, forms, or claims present. |
|---|
Evidence status and limitations
Evidence completeness: UNKNOWN
- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.
At a glance
The checks that decide most of this verdict.
| Malware engines | 8 flagged itVirusTotal | Risk |
|---|---|---|
| Google Safe Browsing | Not listedGoogle | Clear |
| Abuse reports on the host | 0 reportsAbuseIPDB; shared hosting inflates this count | Noted |
| Domain age | 18 years oldRegistered history | Clear |
| Web archive | Archived since 2008Public history exists | Clear |
| Certificate | Encrypted connectionIssued by R12 | Noted |
The page as captured
Key findings
- Automated classification: Sensitive Interaction Risk.
- Domain age: more than 10 years (registration continuity).
- Public web-archive history exists since 2008.
- At least one reputation service TrustSniffer consulted had flagged this domain at assessment time.
Full analysis
Security Alert
Kaspersky, Sophos flagged this site in external intelligence checks, indicating elevated compromise/scam exposure that requires immediate caution.
The website is a minimal parked landing page for autofitness.ru, presenting the domain as available for purchase through the RU-CENTER domain marketplace, with a purchase link and a displayed price.
Scam/Impersonation Risk
The site presents no active commercial service, login workflow, payment form, or brand-impersonation content in the captured landing page. However, this limited and apparently benign presentation does not offset confirmed external threat signals: the domain is reported as blacklisted, and multiple security providers identified malicious characteristics. Runtime inspection also observed substantial external network activity, including non-whitelisted requests and posts, creating a material risk for sensitive interaction despite the absence of visible abuse features on the page. No separate identity inconsistency, phishing form, or impersonation claim was observed in the supplied page evidence. The published contact-channel anomaly is `not applicable` because no contact address is present on the captured page.
- External reputation checks recorded 8 malicious and 1 suspicious detections from 14 evaluated results; Kaspersky and Sophos were among the flagged providers.
- The homepage is a domain-for-sale page with no forms, login fields, password fields, or wallet-connection activity.
- Runtime inspection recorded 22 external XHR requests, 13 external posts, 16 non-whitelisted XHR requests, and 10 non-whitelisted posts across 2 successful runs.
- Domain registration continuity: registered 2008-11-06 and aged 17.79 years; archival records in the scored historical dataset contain 94 snapshots spanning 2008–2025, across 18 tracked years.
Regulatory Verification Notes
The captured page does not establish a real-world operating entity, regulated activity, or licensing basis; its apparent function is limited to brokering the sale of a domain name. Operator and governance disclosures are unclear, and identity verification remains incomplete. This is a transparency and verification gap rather than a standalone finding of fraud, but it is particularly important because the domain's external reputation is materially adverse. No broker match was identified in the supplied third-party dataset, which provides limited contextual reassurance but is not a licensing or regulatory determination.
- The homepage title and visible text identify the asset as a domain offered for sale through the RU-CENTER marketplace, rather than as an operating business.
- No company name, license number, regulatory authority, terms of service, or operating-entity disclosure appears in the captured page content.
- Page-authority data places the site in a low-authority band; this is explanatory context only and does not independently determine legitimacy.
What to Verify Next
Sensitive use should not proceed on the basis of the parked page or its purchase link. Any proposed acquisition should be confirmed by independently navigating to the registrar's known official marketplace rather than relying solely on the domain landing page, and the intended registrant, transfer process, payment protections, and post-purchase control should be documented before funds are committed. If the domain later becomes an operational service, its legal entity, applicable licensing, terms, and security posture should be reassessed from the new content.
- The captured page contains only a sale listing and does not provide an operating-business identity or substantive service documentation.
- The page contains no login or sensitive-data form, so there is no evidence that ordinary account access is required for the current presentation.
- The displayed business model is a registrar-mediated domain sale, not a disclosed regulated financial or investment service.
Summary Verdict
The overall posture is critical trust risk, with legitimacy and real-world operator identity unestablished. The combination of confirmed adverse external detections and insufficient identity context makes the domain unsuitable for credentials, account access, financial activity, or other sensitive interaction.
Infrastructure Integrity
The site resolves directly to RU-CENTER infrastructure in Russia, without a detected CDN or WAF layer and with a directly visible origin candidate. This provides limited defensive separation between the website and its hosting environment; transport encryption is present, but it is domain-validated rather than an assurance of organizational identity.
- Hosted on AS48287, RU-CENTER - JSC _RU-CENTER_, RU; resolved IP: 178.210.92.164.
- No CDN detected; 1 unique IP and 1 likely origin IP were identified.
- TLS certificate issued by R12 with DV validation, valid to 2026-08-25T21:35:37+00:00; 5 days remained at collection time.
Closing Assessment
The appropriate enterprise posture is to block or isolate sensitive interaction with the domain and require independent registrar and operator confirmation before any transaction, credential use, or future service engagement.
Written analysis generated 2026-08-20 by the TrustSniffer Analysis Engine from the evidence in this report.
What the analysis found
2 findings contributed to this verdict, raised by registration and ownership, analysis engine, behaviour in a sandbox, external reputation.
01 Governance Risk
- The public registration record for this domain is incomplete.Registration and ownership
rule:KF_WHOIS_INCOMPLETE
02 Sensitive Interaction Risk
- The analysis matched a pattern TrustSniffer treats as a direct threat to a visitor.Analysis engine
signal:direct_threat - The page sent data to a destination TrustSniffer does not recognise.Behaviour in a sandbox
rule:BEHAV_NONWHITELISTED_POSTS - The page made background requests to destinations TrustSniffer does not recognise.Behaviour in a sandbox
rule:BEHAV_NONWHITELISTED_XHR - The page exchanged network traffic with destinations TrustSniffer does not recognise.Behaviour in a sandbox
rule:BEHAV_NONWHITELISTED_TRAFFIC - Most of what the page loaded came from other domains rather than from this one.Behaviour in a sandbox
rule:BEHAV_EXTERNAL_RATIO_HIGH - An external threat feed lists this domain: either Google Safe Browsing marked it malicious, or a significant number of malware engines flagged it.External reputation
rule:EXT_BLACKLIST_CRITICAL
Identity verification
| Status | UNVERIFIED |
|---|---|
| Identity score | 30/100 |
| Identity verification confidence | 50% |
- No on-site identity signals detected
Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence.
What TrustSniffer observed
First-party facts recorded during the assessment of autofitness.ru.
- The request stayed on autofitness.ru. It was not redirected to another domain. Clear
- Registration is published under RU-CENTER-RU. Clear
- DNS for this domain is served by ru., across 3 name servers. Noted
- The registration is paid up to 2026-11-06. Noted
- The earliest public archive of this site is from 2008-12-29. Clear
- It is hosted on RU-CENTER, from a server in RU. Noted
Domain intelligence
| Registrar | RU-CENTER-RU |
|---|---|
| Hosting | RU-CENTER - JSC _RU-CENTER_, RU |
| Country | RU |
| Server IP | 178.210.92.164 |
| Name servers | ns3.nic.ru., ns4.nic.ru., ns8.nic.ru. |
| SSL issuer | R12 |
| SSL expiry | 2026-08-25 |
| Domain age | 17.79 years (continuous registration) |
| Domain expiry | 2026-11-06 |
| Archive first seen | 2008-12-29 |
| Archive snapshots | Not counted (archive lookup incomplete) |
| Reputation | VirusTotal: 8 flagged | AbuseIPDB: 0 reports | Google Safe Browsing: 0 matches |
About this assessment
A trust score summarises the evidence TrustSniffer could collect about autofitness.ru at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.
TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.