Verdict
pub-1900be17f2994b5580d602f23eb7fb93.r2.dev shows high-risk / scam indicators.
This assessment found strong scam indicators. Do not pay, sign in, or share personal details with this site.
| What this site appears to be | Storage/object 404 error page indicating the requested object is not public or does not exist. No forms or commerce present. Page contains extraneous prompt-injection style header text in the captured HTML which is flagged. |
|---|
Evidence status and limitations
Evidence completeness: UNKNOWN
- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.
At a glance
The checks that decide most of this verdict.
| Malware engines | 15 flagged itVirusTotal | Risk |
|---|---|---|
| Google Safe Browsing | Not listedGoogle | Clear |
| Abuse reports on the host | 0% confidenceAbuseIPDB, 2 reports; shared hosting inflates reports | Clear |
| Domain age | 2 months oldMost scam domains are under a year old | Risk |
| Web archive | Never archivedNo public history of this site | Watch |
| Certificate | Encrypted connectionIssued by YE1 | Noted |
The page as captured
Key findings
- Automated classification: Sensitive Interaction Risk.
- Domain age: less than 1 year (registration continuity).
- At least one reputation service TrustSniffer consulted had flagged this domain at assessment time.
- The operator behind the site could not be independently connected to a real-world brand or person.
Full analysis
Security Alert
Fortinet, Kaspersky, Sophos flagged this site in external intelligence checks, indicating elevated compromise/scam exposure that requires immediate caution.
This website currently presents a storage-object error page rather than an identifiable service: visitors see “Not Found” and “Object not found” messages, instructions concerning public bucket access, and no apparent commercial, transactional, or user-account purpose.
Scam/Impersonation Risk
The site presents a clearly cautionary risk profile. Independent security screening recorded 15 malicious detections, the domain is associated with a confirmed blacklist status, and detections were attributed by Fortinet, Kaspersky, and Sophos. The captured page is only a 404 storage error and contains extraneous prompt-injection-style header text, which is a deception-related signal even though no login form, payment flow, brand impersonation, or phishing form was observed. No conflicting legal-entity names were identified, but the confirmed blacklist and malicious detections are sufficient to establish a material risk for sensitive interaction.
- The homepage returned HTTP 404 content stating “Not Found,” “Object not found,” and “This object does not exist or is not publicly accessible.”
- External security screening recorded 15 malicious detections and confirmed blacklist status; Fortinet, Kaspersky, and Sophos were among the flagged vendors.
- The captured HTML contained prompt-injection-style header text, while page analysis found no forms, login fields, or commerce flow.
Regulatory Verification Notes
The available page does not identify an operating company, regulated activity, license, registration number, or governing jurisdiction; it is an object-storage error page rather than a substantive legal or business presentation. This creates a significant governance and identity-verification gap, and the real-world operator remains unverified. The absence of a broker-dataset match provides no positive licensing or regulatory conclusion. The site's valid transport certificate and identifiable hosting arrangement are technical facts only and do not establish legal status.
- The homepage title was “Not Found,” with no legal, about, terms, licensing, or corporate disclosure content captured.
- The domain registration record places registration in 2026, approximately 72 days before collection.
- Historical capture data records 3 snapshots in 2026.
- The site's TLS certificate is Domain Validated, issued by YE1, and valid through 2026-12-06.
What to Verify Next
Before any sensitive interaction, an institution should confirm whether the intended service is being accessed through an independently published official domain and establish the responsible operator through a trusted, offline or independently sourced channel. Any claimed license or registration should be checked directly against the relevant regulator's public register, and payment or credential activity should remain suspended until those checks produce a consistent result.
- The captured page provides no identifiable service, operator, or transaction workflow to validate.
- The available identity-verification result remains unverified.
- The page's only substantive content concerns storage-object access rather than regulated products or customer terms.
Summary Verdict
The website has a critical trust posture and should be treated as unsuitable for sensitive interaction. The combination of confirmed external threat detections, blacklist status, a non-substantive error page, and unresolved operator identity materially outweighs the limited technical assurances available.
Infrastructure Integrity
The site is delivered through Cloudflare's CDN/WAF, with all observed addresses belonging to CDN edge infrastructure and no origin server address observed. This reduces direct origin exposure but is only a protective hosting characteristic, not evidence that the website or its operator is legitimate. Two abuse reports associated with a shared Cloudflare address were explicitly attributed to shared provider infrastructure, whitelisted, and discounted as evidence against this specific site.
Closing Assessment
Sensitive use should remain suspended unless independent operator, service, and regulatory checks produce consistent and verifiable results.
Written analysis generated 2026-09-22 by the TrustSniffer Analysis Engine from the evidence in this report.
What the analysis found
2 findings contributed to this verdict, raised by registration and ownership, analysis engine, behaviour in a sandbox.
01 Governance Risk
- The public registration record for this domain is incomplete.Registration and ownership
rule:KF_WHOIS_INCOMPLETE
02 Sensitive Interaction Risk
- The analysis matched a pattern TrustSniffer treats as a direct threat to a visitor.Analysis engine
signal:direct_threat - Most of what the page loaded came from other domains rather than from this one.Behaviour in a sandbox
rule:BEHAV_EXTERNAL_RATIO_HIGH
Signals weighed against the site
- AbuseIPDB: 2 reports on hosting IP 2606:4700:311b::6812:362d (Cloudflare, Inc., Content Delivery Network), 0% confidence. The reports are attributed to shared infrastructure, not specifically to this website.
Identity verification
| Status | UNVERIFIED |
|---|---|
| Identity score | 30/100 |
| Identity verification confidence | 50% |
- No on-site identity signals detected
Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence.
What TrustSniffer observed
First-party facts recorded during the assessment of pub-1900be17f2994b5580d602f23eb7fb93.r2.dev.
- The request stayed on pub-1900be17f2994b5580d602f23eb7fb93.r2.dev. It was not redirected to another domain. Clear
- It is hosted on CLOUDFLARENET, from a server in US. Noted
Domain intelligence
| Registrar | Not available |
|---|---|
| Hosting | CLOUDFLARENET - Cloudflare, Inc., US |
| Country | US |
| Server IP | 2606:4700:311b::6812:362d |
| Name servers | Not available |
| SSL issuer | YE1 |
| SSL expiry | 2026-12-06 |
| Domain age | 0.20 years (continuous registration) |
| Domain expiry | Not available |
| Archive first seen | Not available |
| Archive snapshots | 0 |
| Reputation | VirusTotal: 15 flagged | AbuseIPDB: 0% confidence, 2 reports | Google Safe Browsing: 0 matches |
About this assessment
A trust score summarises the evidence TrustSniffer could collect about pub-1900be17f2994b5580d602f23eb7fb93.r2.dev at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.
TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.