Verdict
pub-72295f71e45d431995028c79cf261dae.r2.dev is moderately trusted.
Most signals looked ordinary, and some evidence was missing. Read the checks below before you pay or hand over personal details.
| What this site appears to be | A static object-storage 404 page stating the object is not found or not publicly accessible. No services, forms, or monetization present. |
|---|
Evidence status and limitations
Evidence completeness: UNKNOWN
- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.
At a glance
The checks that decide most of this verdict.
| Malware engines | 5 flagged itVirusTotal | Risk |
|---|---|---|
| Google Safe Browsing | Not listedGoogle | Clear |
| Abuse reports on the host | 0% confidenceAbuseIPDB, 1 report; shared hosting inflates reports | Clear |
| Domain age | Not availableNo registration record was returned | Noted |
| Web archive | Never archivedNo public history of this site | Watch |
| Certificate | Encrypted connectionIssued by YE1 | Noted |
The page as captured
Key findings
- Automated classification: Sensitive Interaction Risk.
- At least one reputation service TrustSniffer consulted had flagged this domain at assessment time.
- The operator behind the site could not be independently connected to a real-world brand or person.
Full analysis
Security Alert
Kaspersky flagged this site in external intelligence checks, indicating elevated compromise/scam exposure that requires immediate caution.
This website currently presents a static object-storage error page stating “Not Found” and indicating that the requested object either does not exist or is not publicly accessible. It exposes no identifiable service, commercial offering, transaction flow, or stated business purpose to a visitor.
Scam/Impersonation Risk
The site has a materially elevated interaction risk because external reputation checks recorded multiple malicious detections and a confirmed blacklist status, including a Tier 1 security-vendor detection. These findings are not explained by the captured page, which contains no visible phishing form, login mechanism, impersonation content, or active service; however, the benign 404 presentation does not resolve the external conflict. No identity inconsistency or direct brand impersonation was observed, but the combination of blacklisting and malicious detections warrants treating the endpoint as unsuitable for credentials, account access, or financial activity.
- External reputation assessment recorded 5 malicious detections, with Kaspersky among the flagged vendors.
- The domain was identified as blacklisted by two external reputation sources.
- The homepage capture returned an object-storage 404 page with no forms, login fields, links, or transaction functions.
- Behavioral inspection recorded no wallet connection, wallet-drainer activity, hidden forms, password submissions, or clipboard manipulation.
Regulatory Verification Notes
The captured page does not identify an operating company, responsible legal entity, regulatory status, or license. This is a disclosure gap rather than independent proof of misconduct, but it prevents meaningful verification of who operates the endpoint or what activity it is intended to support. Identity verification therefore remains unresolved. The available infrastructure and transport signals provide technical continuity only and do not establish operator legitimacy.
- The captured homepage contains only “Not Found,” object-access instructions, and no legal, corporate, or licensing disclosure.
- Hosted on AS13335, CLOUDFLARENET — Cloudflare, Inc., US.
- TLS certificate issued by YE1 using domain validation (DV), valid to 2026-12-06.
- The available broker-reputation dataset recorded no matching broker profile.
What to Verify Next
Before any sensitive interaction, an organization should identify the intended operating entity through an independent corporate or regulatory registry, confirm whether the endpoint belongs to that entity through an independently sourced contact channel, and obtain a functioning public page containing terms, privacy information, and any required licensing disclosures. Security teams should also block or monitor the endpoint until the blacklist findings have been independently resolved and the destination’s business purpose is established.
- The homepage is a 404 object-storage response rather than an operational business or service page.
- No contact, legal, licensing, product, or transaction information was present in the captured content.
- The external reputation conflict remains unresolved by the available page evidence.
Summary Verdict
The website warrants a moderate-trust classification with elevated risk for sensitive interaction. Its legitimacy is not established, its real-world operator is unverified, and the external threat findings create a significant contradiction that outweighs the limited reassurance provided by valid transport security and benign page behavior.
Infrastructure Integrity
Cloudflare CDN/WAF protection is present, and all observed addresses were CDN edge addresses rather than an identified origin server. This reduces direct exposure of the underlying host and can help absorb infrastructure abuse, but it is only a mitigating technical control and does not validate the site’s operator or content. One abuse report associated with a shared Cloudflare address was explicitly discounted because it applied to shared provider infrastructure rather than being attributable to this site.
Closing Assessment
Sensitive actions should remain suspended unless independent ownership, purpose, and reputation checks produce a clear resolution of the external threat findings.
Written analysis generated 2026-09-19 by the TrustSniffer Analysis Engine from the evidence in this report.
What the analysis found
2 findings contributed to this verdict, raised by registration and ownership, analysis engine, behaviour in a sandbox.
01 Governance Risk
- The public registration record for this domain is incomplete.Registration and ownership
rule:KF_WHOIS_INCOMPLETE
02 Sensitive Interaction Risk
- The analysis matched a pattern TrustSniffer treats as a direct threat to a visitor.Analysis engine
signal:direct_threat - The structure of the page changed sharply while it was loading.Behaviour in a sandbox
rule:BEHAV_DOM_DENSITY_SPIKE - Most of what the page loaded came from other domains rather than from this one.Behaviour in a sandbox
rule:BEHAV_EXTERNAL_RATIO_HIGH
Signals weighed against the site
- AbuseIPDB: 1 report on hosting IP 2606:4700:311b::6812:3222 (Cloudflare, Inc., Content Delivery Network), 0% confidence. The reports are attributed to shared infrastructure, not specifically to this website.
Identity verification
| Status | UNVERIFIED |
|---|---|
| Identity score | 30/100 |
| Identity verification confidence | 50% |
- No on-site identity signals detected
Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence.
What TrustSniffer observed
First-party facts recorded during the assessment of pub-72295f71e45d431995028c79cf261dae.r2.dev.
- The request stayed on pub-72295f71e45d431995028c79cf261dae.r2.dev. It was not redirected to another domain. Clear
- It is hosted on CLOUDFLARENET, from a server in US. Noted
Domain intelligence
| Registrar | Not available |
|---|---|
| Hosting | CLOUDFLARENET - Cloudflare, Inc., US |
| Country | US |
| Server IP | 2606:4700:311b::6812:3222 |
| Name servers | Not available |
| SSL issuer | YE1 |
| SSL expiry | 2026-12-06 |
| Domain age | Not available (no registration date was returned) |
| Domain expiry | Not available |
| Archive first seen | Not available |
| Archive snapshots | 0 |
| Reputation | VirusTotal: 5 flagged | AbuseIPDB: 0% confidence, 1 report | Google Safe Browsing: 0 matches |
About this assessment
A trust score summarises the evidence TrustSniffer could collect about pub-72295f71e45d431995028c79cf261dae.r2.dev at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.
TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.