Verdict
poljfak.edu.rs shows high-risk / scam indicators.
This assessment found strong scam indicators. Do not pay, sign in, or share personal details with this site.
| What this site appears to be | A WordPress-hosted informational page for a faculty (Poljoprivredni) that lists results, notices and a WebMail link for institutional email addresses. |
|---|
Evidence status and limitations
Evidence completeness: UNKNOWN
- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.
At a glance
The checks that decide most of this verdict.
| Malware engines | 7 flagged itVirusTotal | Risk |
|---|---|---|
| Google Safe Browsing | Not listedGoogle | Clear |
| Abuse reports on the host | 0 reportsAbuseIPDB; shared hosting inflates this count | Noted |
| Domain age | 5.7 years oldRegistered history | Clear |
| Web archive | Archived since 2021Public history exists | Clear |
| Certificate | Encrypted connectionIssued by YR1 | Noted |
The page as captured
Key findings
- Automated classification: Sensitive Interaction Risk.
- Domain age: 3 to 10 years (registration continuity).
- Public web-archive history exists since 2021.
- At least one reputation service TrustSniffer consulted had flagged this domain at assessment time.
Full analysis
Overview
This website presents itself as the official website of an agricultural faculty, using a WordPress-based informational format to publish results, notices, and links to institutional WebMail services for faculty email addresses.
Scam/Impersonation Risk
The site’s visible content is consistent with a low-interaction academic information page and does not itself display obvious fraud features, login forms, financial offers, or brand-impersonation elements. However, that benign presentation is materially contradicted by confirmed blacklist status and multiple external malicious detections. Runtime inspection also recorded non-whitelisted external requests and substantial DOM changes after interaction; these observations do not independently establish malicious intent, but they reinforce the need to treat the site as unsuitable for sensitive interaction. No conflicting legal-entity names or direct impersonation indicators were observed.
- The homepage identifies itself as “Poljoprivredni – My WordPress Blog,” describes the site as the official faculty website, and presents results, notices, and WebMail information.
- External reputation assessment recorded 7 malicious detections and 1 suspicious detection, with the domain also marked as blacklisted.
- Behavioral testing recorded 2 external XHR requests, 2 external POST requests, 4 non-whitelisted external network events, and a maximum post-interaction DOM difference of 908 elements.
Regulatory Verification Notes
The apparent academic purpose and the “edu.rs” domain suffix provide contextual support for the site’s stated institutional role, but they do not independently verify the real-world operator. The available content does not present a licensing claim or registration number; for an informational faculty site this may be appropriate to its stated purpose, but it remains a disclosure limitation if the site is used for any service beyond institutional communication. The registration record names Stanco d.o.o. as registrar and identifies POLJOPRIVREDNI FAKULTET U KRUŠEVCU as the registrant; these records are relevant identity signals, not conclusive proof of current control. A valid domain-validated certificate confirms encrypted transport, not institutional authenticity.
- The homepage states that it is the official faculty website and links to faculty email WebMail services.
- The domain was registered on 2020-12-11 and is approximately 5.69 years old; the registrar is Stanco d.o.o.
- The site’s TLS certificate is issued by YR1, uses DV validation, and is valid to 2026-09-19.
What to Verify Next
Before any credential submission or other sensitive interaction, an institution or prospective user should confirm the domain and WebMail destination through an independently obtained faculty contact channel, such as a telephone number or directory entry sourced outside the website. The relevant academic institution should also confirm that the domain remains officially assigned to it and that the displayed contact and WebMail links are current. Any request that falls outside ordinary faculty notices should be validated directly with the institution before proceeding.
- The homepage contains no sensitive form and no embedded login form, but it does provide a WebMail link for institutional addresses.
- The displayed institutional identity and contact destinations should be checked against an independently sourced faculty directory or official administrative channel.
- The site is classified within the academic “edu.rs” namespace, while the independent identity connection remains unverified.
Summary Verdict
The overall posture is critical and unsuitable for sensitive interaction. Although the site presents a plausible academic information purpose and contains no obvious on-page fraud mechanics, the confirmed adverse reputation signals materially outweigh that presentation. The site should therefore be treated as potentially compromised, misdirected, or otherwise unsafe for credentials, account access, or financial activity.
Infrastructure Integrity
The website is protected by a CDN/WAF layer, which provides a mitigating defensive control but does not establish legitimacy. The observed address was an edge address, and the origin server was not observable in this analysis.
- Hosted on AS24940, HETZNER-AS – Hetzner Online GmbH, DE.
- Observed edge IP: 162.55.0.170; country associated with the hosting infrastructure: DE.
- CDN/WAF protection was detected, with 1 observed edge IP and 0 likely origin candidates.
Closing Assessment
Sensitive actions should be withheld unless the institution independently confirms the domain, current site control, and every destination involved in the interaction.
Written analysis generated 2026-08-21 by the TrustSniffer Analysis Engine from the evidence in this report.
What the analysis found
2 findings contributed to this verdict, raised by registration and ownership, analysis engine, behaviour in a sandbox, external reputation.
01 Governance Risk
- The public registration record for this domain is incomplete.Registration and ownership
rule:KF_WHOIS_INCOMPLETE
02 Sensitive Interaction Risk
- The analysis matched a pattern TrustSniffer treats as a direct threat to a visitor.Analysis engine
signal:direct_threat - Most of what the page loaded came from other domains rather than from this one.Behaviour in a sandbox
rule:BEHAV_EXTERNAL_RATIO_HIGH - The page exchanged network traffic with destinations TrustSniffer does not recognise.Behaviour in a sandbox
rule:BEHAV_NONWHITELISTED_TRAFFIC - The page sent data to a destination TrustSniffer does not recognise.Behaviour in a sandbox
rule:BEHAV_NONWHITELISTED_POSTS - The structure of the page changed sharply while it was loading.Behaviour in a sandbox
rule:BEHAV_DOM_DENSITY_SPIKE - An external threat feed lists this domain: either Google Safe Browsing marked it malicious, or a significant number of malware engines flagged it.External reputation
rule:EXT_BLACKLIST_CRITICAL
Identity verification
| Status | UNVERIFIED |
|---|---|
| Identity score | 55/100 |
| Identity verification confidence | 60% |
- Identity verified on page
Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence.
What TrustSniffer observed
First-party facts recorded during the assessment of poljfak.edu.rs.
- The request stayed on poljfak.edu.rs. It was not redirected to another domain. Clear
- Registration is published under Stanco d.o.o.. Clear
- DNS for this domain is served by dnsserve.rs, across 2 name servers. Noted
- The registration is paid up to 2026-12-11. Noted
- The earliest public archive of this site is from 2021-12-21. Clear
- It is hosted on HETZNER-AS, from a server in DE. Noted
Domain intelligence
| Registrar | Stanco d.o.o. |
|---|---|
| Hosting | HETZNER-AS - Hetzner Online GmbH, DE |
| Country | DE |
| Server IP | 162.55.0.170 |
| Name servers | benz.dnsserve.rs, benz2.dnsserve.rs |
| SSL issuer | YR1 |
| SSL expiry | 2026-09-19 |
| Domain age | 5.69 years (continuous registration) |
| Domain expiry | 2026-12-11 |
| Archive first seen | 2021-12-21 |
| Archive snapshots | Not counted (archive lookup incomplete) |
| Reputation | VirusTotal: 7 flagged | AbuseIPDB: 0 reports | Google Safe Browsing: 0 matches |
About this assessment
A trust score summarises the evidence TrustSniffer could collect about poljfak.edu.rs at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.
TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.