Verdict
diwa.tg shows high-risk / scam indicators.
This assessment found strong scam indicators. Do not pay, sign in, or share personal details with this site.
| What this site appears to be | GPT summary status=skipped | No usable content for GPT summary (clean/dom/html all empty) |
|---|
Evidence status and limitations
Evidence completeness: UNKNOWN
- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.
At a glance
The checks that decide most of this verdict.
| Malware engines | 9 flagged itVirusTotal | Risk |
|---|---|---|
| Google Safe Browsing | Not listedGoogle | Clear |
| Abuse reports on the host | 0 reportsAbuseIPDB; shared hosting inflates this count | Noted |
| Domain age | 4.7 years oldRegistered history | Clear |
| Web archive | Archived since 2021236 snapshots | Clear |
| Certificate | Encrypted connectionIssued by YR2 | Noted |
The page as captured
No screenshot is retained for this report.
Key findings
- Automated classification: Sensitive Interaction Risk.
- Domain age: 3 to 10 years (registration continuity).
- Public web-archive history exists since 2021.
- At least one reputation service TrustSniffer consulted had flagged this domain at assessment time.
Full analysis
Overview
diwa.tg is an online domain whose supplied visitor-facing evidence does not establish a clear business model, operator, or regulated service; its assessed posture is instead associated with sensitive-interaction risk and requires security-forward handling.
Scam/Impersonation Risk
Confirmed external threat detections create a serious contradiction to ordinary website legitimacy. The domain is blacklisted by multiple external sources, including nine malicious detections and one suspicious detection, although no separate identity inconsistency, brand impersonation, or phishing contradiction is established in the supplied findings. The domain’s continuous archival presence is a positive provenance signal, but it does not offset the current external threat detections or independently prove who operates the site.
- External reputation telemetry records 9 malicious detections, 1 suspicious detection, and an external blacklist hit for the domain.
- Archive records show 236 snapshots from 2021-11-30 through 2026-02-03, covering 6 tracked years with a maximum observed gap of 1 year.
- The domain has a registration-continuity age of approximately 4.72 years, dating to approximately 2021.
Regulatory Verification Notes
The operator’s real-world identity remains unverified, and the site’s legal, governance, and licensing disclosures are unclear in the supplied material. No licensing or registration claim is sufficiently established to support regulated-service reliance. This is a verification gap rather than a standalone finding of fraud; however, combined with the confirmed blacklist status, it materially limits the basis for sensitive engagement. The available third-party broker context contains no matching result and therefore provides no affirmative regulatory or identity support.
- Hosting telemetry identifies AS19318, IS-AS-1 – Interserver, Inc, US.
- Transport encryption uses a DV TLS certificate issued by YR2, valid through 2026-10-11T21:28:34+00:00.
- The site’s legal and regulatory disclosure state is recorded as unclear, with independent identity verification unresolved.
What to Verify Next
Before any sensitive interaction, an independent check should identify the legal operator, confirm whether the relevant activity requires authorization, and validate that authorization directly through the applicable regulator or corporate registry. Official contact channels should be confirmed through an independently sourced route rather than relying solely on information presented by the domain. Until those checks succeed, credentials, account access, payments, transfers, and other irreversible actions should not be initiated.
- The decisive risk basis is the combination of external malicious detections and a confirmed blacklist status.
- The supplied material does not establish a verified legal operator or confirmed licensing basis.
- The captured behavioral assessment recorded no wallet-connection, wallet-drainer, external-post, or external-XHR activity, but this absence does not resolve the external reputation contradiction.
Summary Verdict
The overall posture is critical and unsuitable for sensitive interaction. Historical continuity and valid transport encryption are insufficient to overcome the confirmed external threat detections, while operator identity and regulatory standing remain unresolved.
Infrastructure Integrity
The site resolves through Interserver infrastructure in the United States, with no CDN or WAF detected and two addresses assessed as likely origin addresses. The absence of an identified protective edge layer provides limited mitigation and leaves the hosting arrangement more directly exposed, although infrastructure characteristics alone do not establish malicious intent.
Closing Assessment
Prospective users should retain a non-sensitive, observation-only posture and defer login, credential submission, payments, transfers, or other financial activity until independent identity and authorization checks are completed.
Written analysis generated 2026-08-20 by the TrustSniffer Analysis Engine from the evidence in this report.
What the analysis found
2 findings contributed to this verdict, raised by registration and ownership, analysis engine, external reputation.
01 Governance Risk
- The public registration record for this domain is incomplete.Registration and ownership
rule:KF_WHOIS_INCOMPLETE
02 Sensitive Interaction Risk
- The analysis matched a pattern TrustSniffer treats as a direct threat to a visitor.Analysis engine
signal:direct_threat - An external threat feed lists this domain: either Google Safe Browsing marked it malicious, or a significant number of malware engines flagged it.External reputation
rule:EXT_BLACKLIST_CRITICAL
Identity verification
| Status | UNKNOWN |
|---|---|
| Identity score | 50/100 |
| Identity verification confidence | 30% |
- AI page analysis unavailable (page captured; identity not AI-verified)
Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence.
What TrustSniffer observed
First-party facts recorded during the assessment of diwa.tg.
- The request for diwa.tg ended on chromewebdata, a different domain. Watch
- Registration is published under ..........NETMASTER SARL. Clear
- The earliest public archive of this site is from 2021-11-30. Clear
- It is hosted on IS-AS-1, from a server in US. Noted
Domain intelligence
| Registrar | ..........NETMASTER SARL |
|---|---|
| Hosting | IS-AS-1 - Interserver, Inc, US |
| Country | US |
| Server IP | 2a00:7ee0:9:3:54:1:0:c9 |
| Name servers | Not available |
| SSL issuer | YR2 |
| SSL expiry | 2026-10-11 |
| Domain age | 4.72 years (continuous registration) |
| Domain expiry | Not available |
| Archive first seen | 2021-11-30 |
| Archive snapshots | 236 |
| Reputation | VirusTotal: 9 flagged | AbuseIPDB: 0 reports | Google Safe Browsing: 0 matches |
About this assessment
A trust score summarises the evidence TrustSniffer could collect about diwa.tg at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.
TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.