Verdict
ficus.in is low-trust and potentially risky.
Several risk patterns were present. Do not send money or personal details until you have verified this business another way.
| What this site appears to be | Marketing and portfolio page for an engineering/design firm (Ficus – Instinct Engineering). Contains service descriptions, contact details, address in Coimbatore, and social links. No payment or credential collection elements found. |
|---|
Compromised host notice
A threat-intelligence feed listed a file on ficus.in as hosting scam content (last seen 2026-09-15). TrustSniffer's evidence indicates that the site itself was compromised: the listing concerns a file placed on it by someone else, and the site's owner is most likely a victim, not the actor.
Until the file is removed, downloading anything from this site is not safe. If you run this site, remove the listed file, update the site software and its plugins, change its passwords and review it for other unauthorized changes.
Evidence status and limitations
Evidence completeness: UNKNOWN
- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.
At a glance
The checks that decide most of this verdict.
| Malware engines | 4 flagged itVirusTotal | Risk |
|---|---|---|
| Google Safe Browsing | Not listedGoogle | Clear |
| Abuse reports on the host | 0% confidenceAbuseIPDB, 1 report; shared hosting inflates reports | Clear |
| Domain age | 19 years oldRegistered history | Clear |
| Web archive | Archived since 2008271 snapshots | Clear |
| Certificate | Encrypted connectionIssued by YR2 | Noted |
The page as captured
Key findings
- Automated classification: Sensitive Interaction Risk.
- Domain age: more than 10 years (registration continuity).
- Public web-archive history exists since 2008.
- At least one reputation service TrustSniffer consulted had flagged this domain at assessment time.
Full analysis
Security Alert
Fortinet, Sophos flagged this site in external intelligence checks, indicating elevated compromise/scam exposure that requires immediate caution.
Ficus – Instinct Engineering is a corporate marketing and portfolio website presenting engineering and design services for heavy and light industry, with sections for sectors, services, projects, company information, employment, insights, contact, and bid requests. Its apparent business model is to attract B2B clients and obtain professional-services project work rather than process consumer payments or credentials directly.
Scam/Impersonation Risk
The site presents as a conventional engineering-services business, and its homepage contains no login form, sensitive submission form, payment flow, wallet connection, or other high-risk conversion mechanism. However, this benign presentation is outweighed by confirmed external threat detections and blacklist status associated with the domain. No conflicting legal-entity names or direct brand-impersonation indicators were observed in the supplied page findings, but the external signals create a material contradiction that warrants treating sensitive interaction with the site as unsafe. The single hosting-IP abuse report is not treated as evidence against the website itself because it was attributed to shared provider infrastructure with zero confidence. Evidence:
- The homepage identifies “Ficus – Instinct Engineering,” describes engineering and design services, and provides “Request bid” and “Reach Us” pathways.
- Page analysis found no login form, hidden sensitive form, password submission, wallet connection, or payment element.
- External reputation checks recorded 4 malicious detections, with Fortinet and Sophos among the flagged vendors, and confirmed blacklist status from two sources.
- The hosting-IP report concerned shared data-center infrastructure and was explicitly discounted as provider-level attribution.
Regulatory Verification Notes
The available material supports an apparent corporate-services identity but does not independently verify the operating entity or establish regulatory authorization. The site identifies the business as Ficus – Instinct Engineering and supplies a Coimbatore address, contact details, and links to LinkedIn and Facebook; identity verification therefore remains likely rather than proven. No licensing claim, registration number, or regulatory authority is presented in the supplied business content. That omission is a transparency and verification gap, not by itself evidence of a scam. The website’s generic template text, including placeholder-style service, testimonial, and company-description language, further limits the strength of its corporate disclosures. Evidence:
- The homepage and company-content areas identify Ficus – Instinct Engineering and describe engineering services for heavy and light industry.
- The contact content supplies a Coimbatore address and social links to LinkedIn and Facebook.
- WHOIS records show registration on 2010-04-18 through Endurance International Group India Private Limited, with Ficus Consulting India Private Limited listed as the organization.
- The domain has 271 archive snapshots spanning 2008–2025, with 18 years tracked, indicating substantial historical continuity rather than a newly created web presence.
- Hosted on AS46606, Unified Layer, US; TLS certificate issued by YR2 using DV validation, valid to 2026-10-23.
What to Verify Next
Before any sensitive engagement, the prospective counterparty should independently confirm the company’s legal registration and any sector-specific authorization through the relevant Indian corporate or regulatory registry, using contact details obtained independently of the website. Any bid, contract, invoice, bank-account instruction, or document-transfer request should be validated through an offline or independently sourced business contact. Account login, credential submission, and financial transactions should not be undertaken on the basis of this website’s presentation alone. Evidence:
- The supplied business content requests client engagement and bids but does not provide a license number or named licensing authority.
- The site publishes contact and social-channel information that can be cross-checked against independently sourced corporate records.
- Confirmed external threat detections and blacklist status require independent validation of the counterparty before sensitive interaction.
Summary Verdict
The website has a credible-looking engineering-services presentation and a long-running domain history, but the confirmed blacklist and malicious threat detections produce a low-trust posture. The available evidence is insufficient to support sensitive interaction or to treat the apparent business identity as independently established.
Infrastructure Integrity
The site resolves directly to Unified Layer hosting without a detected CDN or WAF layer, leaving the hosting environment as the primary observable delivery infrastructure. Transport encryption is present, but the certificate is domain-validated only; these controls provide baseline technical protection and do not offset the external reputation contradiction.
- Infrastructure resolution identified one likely origin IP and no CDN edge IPs or detected CDN vendors.
- The hosting environment is operated by Unified Layer in the United States, with no protective CDN/WAF layer identified.
Closing Assessment
Treat the site as suitable only for limited, non-sensitive review while independently validating the business, its legal standing, and every proposed transaction or document exchange through trusted external channels.
Written analysis generated 2026-09-22 by the TrustSniffer Analysis Engine from the evidence in this report.
What the analysis found
1 finding contributed to this verdict, raised by analysis engine.
01 Sensitive Interaction Risk
- The analysis matched a pattern TrustSniffer treats as a direct threat to a visitor.Analysis engine
signal:direct_threat
Signals weighed against the site
- AbuseIPDB: 1 report on hosting IP 162.251.80.25 (Unified Layer, Data Center/Web Hosting/Transit), 0% confidence. The reports are attributed to shared infrastructure, not specifically to this website.
Identity verification
| Status | LIKELY |
|---|---|
| Identity score | 76/100 |
| Identity verification confidence | 76% |
- Trusted social count=2
Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence.
What TrustSniffer observed
First-party facts recorded during the assessment of ficus.in.
- The request stayed on ficus.in. It was not redirected to another domain. Clear
- Registration is published under Endurance International Group India Private Limited. Clear
- DNS for this domain is served by webhostbox.net, across 2 name servers. Noted
- The registration is paid up to 2028-04-18. Clear
- The earliest public archive of this site is from 2008-02-03. Clear
- It is hosted on UNIFIEDLAYER-AS-1, from a server in US. Noted
Domain intelligence
| Registrar | Endurance International Group India Private Limited |
|---|---|
| Hosting | UNIFIEDLAYER-AS-1 - Unified Layer, US |
| Country | US |
| Server IP | 162.251.80.25 |
| Name servers | ns1.cp-14.webhostbox.net, ns2.cp-14.webhostbox.net |
| SSL issuer | YR2 |
| SSL expiry | 2026-10-23 |
| Domain age | 18.63 years (continuous registration) |
| Domain expiry | 2028-04-18 |
| Archive first seen | 2008-02-03 |
| Archive snapshots | 271 |
| Reputation | VirusTotal: 4 flagged | AbuseIPDB: 0% confidence, 1 report | Google Safe Browsing: 0 matches |
About this assessment
A trust score summarises the evidence TrustSniffer could collect about ficus.in at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.
TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.