Verdict
gfgxcx.com is low-trust and potentially risky.
Several risk patterns were present. Do not send money or personal details until you have verified this business another way.
| What this site appears to be | A bare web directory index listing multiple .zip files with timestamps and sizes. No site branding, contact, or explanatory content; potential risk from downloading unvetted archives. |
|---|
Evidence status and limitations
Evidence completeness: UNKNOWN
- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.
At a glance
The checks that decide most of this verdict.
| Malware engines | 1 flagged itVirusTotal | Risk |
|---|---|---|
| Google Safe Browsing | Not listedGoogle | Clear |
| Abuse reports on the host | 0 reportsAbuseIPDB; shared hosting inflates this count | Noted |
| Domain age | 7 days oldMost scam domains are under a year old | Risk |
| Web archive | Archived since 2026Public history exists | Clear |
| Certificate | Encrypted connectionIssued by Sectigo Public Server Authentication CA DV R36 | Noted |
The page as captured
Key findings
- Automated classification: Sensitive Interaction Risk.
- Domain age: less than 1 year (registration continuity).
- Public web-archive history exists since 2026.
- At least one reputation service TrustSniffer consulted had flagged this domain at assessment time.
Full analysis
Security Alert
Fortinet flagged this site in external intelligence checks, indicating elevated compromise/scam exposure that requires immediate caution.
The site is a bare directory index rather than a conventional branded service: its homepage presents “Index of /” and exposes downloadable ZIP archives, including files named “LocalOffice1.zip” and other opaque filenames, with no visible explanation of ownership, purpose, or monetization.
Scam/Impersonation Risk
The site presents a high-risk interaction profile because its only visible function is direct archive downloading, while the files have no stated provenance or explanation. Independent reputation checks identify a confirmed blacklist result and additional malicious or suspicious detections; these signals materially outweigh the fact that the page did not display a login form, payment form, or overt brand impersonation. No conflicting legal-entity names were observed, but the absence of a recognizable identity does not resolve the external threat indication. The appropriate interpretation is a confirmed reputational contradiction with elevated risk around downloading or executing the listed files.
- The homepage is titled “Index of /” and exposes direct ZIP downloads, including “LocalOffice1.zip,” “c.f.g.hf.t.221.zip,” and “d.f.r.qe.114.zip.”
- The homepage contains approximately 156 characters of directory text and provides no file provenance, explanatory business content, branding, or contact route.
- External reputation assessment records a confirmed blacklist result, with 1 malicious and 2 suspicious detections among evaluated results.
Regulatory Verification Notes
The website does not present an identifiable operating entity, licensing statement, registration number, governing terms, or other substantive legal disclosure on the observed homepage. Its business purpose is therefore unclear, and the available evidence does not independently verify the operator’s identity. Ownership opacity is a governance limitation relevant to accountability, while the use of a named registrar is only an administrative fact and does not establish legitimacy. No broker match was identified in the available third-party context, but that absence is not a licensing or regulatory determination.
- The homepage contains no visible company name, license claim, registration number, terms, or regulatory disclosure.
- Domain registration telemetry records creation on 2026-09-14, with an age of 0.02 years.
- The domain is registered through Metaregistrar BV; the observed registration expiry is 2027-09-14.
What to Verify Next
Before any interaction beyond passive viewing, an organization should obtain the operator’s legal identity and independently confirm it through authoritative corporate or regulatory records. The provenance and integrity of each archive should be established through a trusted, separate channel, with any downloaded material handled only in an isolated analysis environment and not opened on production systems. Security teams should also compare the domain and file hashes against internal detections before permitting access.
- The homepage supplies downloadable ZIP files but no provenance, publisher identity, checksum, or explanatory documentation.
- The homepage has no contact details or independent support channel through which ownership or file origin can be confirmed.
- The observed page is a directory listing with direct-download behavior and no sensitive form or authenticated workflow.
Summary Verdict
The website has a low-trust posture and should be treated as an elevated-risk, unverified destination. The available evidence does not establish a legitimate operating identity, and the confirmed external reputation contradiction makes sensitive interaction or file acquisition inappropriate without independent validation.
Infrastructure Integrity
The site is served through CDN/WAF-protected edge infrastructure associated with DigitalOcean, LLC, in the United States; the observed origin was not independently visible. This protection may reduce direct exposure of the underlying host, but it is only a mitigating infrastructure characteristic and does not offset the site-level reputation and provenance concerns.
- Hosted on AS14061 (DigitalOcean, LLC, US).
- The infrastructure record identifies one observed edge IP, 178.128.118.22, with no observable origin candidate.
- TLS uses a DV certificate issued by Sectigo Public Server Authentication CA DV R36, valid to 2027-04-09.
Closing Assessment
Prospective users should limit activity to non-executing observation and require independent operator and file-provenance validation before permitting any further interaction.
Written analysis generated 2026-09-24 by the TrustSniffer Analysis Engine from the evidence in this report.
What the analysis found
2 findings contributed to this verdict, raised by registration and ownership, analysis engine.
01 Governance Risk
- The public registration record for this domain is incomplete.Registration and ownership
rule:KF_WHOIS_INCOMPLETE
02 Sensitive Interaction Risk
- The analysis matched a pattern TrustSniffer treats as a direct threat to a visitor.Analysis engine
signal:direct_threat
Identity verification
| Status | UNVERIFIED |
|---|---|
| Identity score | 30/100 |
| Identity verification confidence | 50% |
- No on-site identity signals detected
Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence.
What TrustSniffer observed
First-party facts recorded during the assessment of gfgxcx.com.
- The request stayed on gfgxcx.com. It was not redirected to another domain. Clear
- Registration is published under Metaregistrar BV. Clear
- DNS for this domain is served by share-dns.com, across 2 name servers. Noted
- The registration is paid up to 2027-09-14. Noted
- The earliest public archive of this site is from 2026-09-14. Clear
- It is hosted on DIGITALOCEAN-ASN, from a server in US. Noted
Domain intelligence
| Registrar | Metaregistrar BV |
|---|---|
| Hosting | DIGITALOCEAN-ASN - DigitalOcean, LLC, US |
| Country | US |
| Server IP | 178.128.118.22 |
| Name servers | A10.SHARE-DNS.COM, B10.SHARE-DNS.NET |
| SSL issuer | Sectigo Public Server Authentication CA DV R36 |
| SSL expiry | 2027-04-09 |
| Domain age | 0.02 years (continuous registration) |
| Domain expiry | 2027-09-14 |
| Archive first seen | 2026-09-14 |
| Archive snapshots | Not counted (archive lookup incomplete) |
| Reputation | VirusTotal: 1 flagged | AbuseIPDB: 0 reports | Google Safe Browsing: 0 matches |
About this assessment
A trust score summarises the evidence TrustSniffer could collect about gfgxcx.com at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.
TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.