Verdict
pub-f9f2f77b53d14531ba49bd6d0bd18740.r2.dev is low-trust and potentially risky.
Several risk patterns were present. Do not send money or personal details until you have verified this business another way.
| What this site appears to be | 404 error page indicating the requested object is not found or not publicly accessible. No forms, calls-to-action, or monetization present. |
|---|
Evidence status and limitations
Evidence completeness: UNKNOWN
- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.
At a glance
The checks that decide most of this verdict.
| Malware engines | 9 flagged itVirusTotal | Risk |
|---|---|---|
| Google Safe Browsing | Not listedGoogle | Clear |
| Abuse reports on the host | 0% confidenceAbuseIPDB, 1 report; shared hosting inflates reports | Clear |
| Domain age | Not availableNo registration record was returned | Noted |
| Web archive | Never archivedNo public history of this site | Watch |
| Certificate | Encrypted connectionIssued by YE1 | Noted |
The page as captured
Key findings
- Automated classification: Sensitive Interaction Risk.
- At least one reputation service TrustSniffer consulted had flagged this domain at assessment time.
- The operator behind the site could not be independently connected to a real-world brand or person.
Full analysis
Security Alert
Fortinet, Kaspersky, Sophos flagged this site in external intelligence checks, indicating elevated compromise/scam exposure that requires immediate caution.
This website is a subdomain-hosted object-storage endpoint that currently presents a generic “Not Found” error stating that the requested object does not exist or is not publicly accessible; its apparent purpose cannot be established from the available page, which contains no visible service, transaction, or user-account flow.
Scam/Impersonation Risk
The site presents a high-risk interaction posture because external threat intelligence records a confirmed blacklist condition and multiple malicious detections, including detections from Fortinet, Kaspersky, and Sophos. These signals are materially more significant than the benign appearance of the 404 page and are consistent with the authoritative low-trust assessment. The available evidence does not establish brand impersonation or a conflicting legal identity, so the concern is a technical-reputation contradiction rather than proven impersonation. A separate single abuse report was attributed to shared infrastructure, was whitelisted, and carried zero confidence; it is therefore not treated as site-specific evidence.
- The homepage returns HTTP 404 content stating “Object not found” and provides no forms, calls-to-action, monetization, or login mechanism.
- External reputation assessment records 9 malicious detections and a confirmed blacklist condition.
- The rendered page contains no detected login form, hidden form, wallet connection, clipboard manipulation, or suspicious inline script.
Regulatory Verification Notes
The accessible site content does not identify an operating company, regulated entity, licensing authority, or license number. Because the available page is only an object-not-found response, this is a disclosure and verification gap rather than independent proof of fraud; however, the operator identity remains unverified and the site does not provide a sufficient basis for regulatory reliance. Transport security and identifiable hosting infrastructure are positive technical controls, but they do not establish the operator’s legitimacy or regulatory status.
- The homepage is titled “Not Found” and contains no company, terms, privacy, licensing, or regulatory disclosure.
- The site is served on AS13335 through CLOUDFLARENET - Cloudflare, Inc., US.
- The TLS certificate is issued by YE1, uses Domain Validation (DV), and is valid to 2026-12-06 05:31:56 UTC.
What to Verify Next
Before any sensitive interaction, an institution should identify the intended service through an independently sourced business record, confirm any claimed authorization directly with the relevant regulator, and obtain the operator’s legal name and accountable support channel through an offline or independently verified route. Credentials, payment details, fund transfers, and other sensitive submissions should not be made until those checks resolve both the identity gap and the confirmed reputation conflict.
- The homepage supplies no active service flow or official business identity from which licensing could be independently confirmed.
- The accessible content offers no terms, privacy notice, regulated-entity statement, or contact page to support an independent verification trail.
Summary Verdict
The website has a low-trust posture with elevated risk for sensitive interaction. Its current content is non-operational, its real-world operator is not independently established, and the confirmed external reputation conflict outweighs the limited assurance provided by its technical configuration.
Infrastructure Integrity
The site is protected by Cloudflare CDN/WAF infrastructure, and all observed addresses are edge servers rather than an exposed origin. This reduces direct origin exposure and can mitigate routine infrastructure abuse, but protective edge hosting is a mitigating control only and does not validate the underlying website or operator.
Closing Assessment
The appropriate business posture is to suspend credential, payment, and financial interaction unless independent identity, authorization, and reputation checks produce clear, corroborated results.
Written analysis generated 2026-09-24 by the TrustSniffer Analysis Engine from the evidence in this report.
What the analysis found
2 findings contributed to this verdict, raised by registration and ownership, analysis engine, behaviour in a sandbox.
01 Governance Risk
- The public registration record for this domain is incomplete.Registration and ownership
rule:KF_WHOIS_INCOMPLETE
02 Sensitive Interaction Risk
- The analysis matched a pattern TrustSniffer treats as a direct threat to a visitor.Analysis engine
signal:direct_threat - The structure of the page changed sharply while it was loading.Behaviour in a sandbox
rule:BEHAV_DOM_DENSITY_SPIKE - Most of what the page loaded came from other domains rather than from this one.Behaviour in a sandbox
rule:BEHAV_EXTERNAL_RATIO_HIGH
Signals weighed against the site
- AbuseIPDB: 1 report on hosting IP 2606:4700:311b::6812:3222 (Cloudflare, Inc., Content Delivery Network), 0% confidence. The reports are attributed to shared infrastructure, not specifically to this website.
Identity verification
| Status | UNVERIFIED |
|---|---|
| Identity score | 30/100 |
| Identity verification confidence | 50% |
- No on-site identity signals detected
Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence.
What TrustSniffer observed
First-party facts recorded during the assessment of pub-f9f2f77b53d14531ba49bd6d0bd18740.r2.dev.
- The request stayed on pub-f9f2f77b53d14531ba49bd6d0bd18740.r2.dev. It was not redirected to another domain. Clear
- It is hosted on CLOUDFLARENET, from a server in US. Noted
Domain intelligence
| Registrar | Not available |
|---|---|
| Hosting | CLOUDFLARENET - Cloudflare, Inc., US |
| Country | US |
| Server IP | 2606:4700:311b::6812:3222 |
| Name servers | Not available |
| SSL issuer | YE1 |
| SSL expiry | 2026-12-06 |
| Domain age | Not available (no registration date was returned) |
| Domain expiry | Not available |
| Archive first seen | Not available |
| Archive snapshots | 0 |
| Reputation | VirusTotal: 9 flagged | AbuseIPDB: 0% confidence, 1 report | Google Safe Browsing: 0 matches |
About this assessment
A trust score summarises the evidence TrustSniffer could collect about pub-f9f2f77b53d14531ba49bd6d0bd18740.r2.dev at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.
TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.