Verdict
weroll-byte-welcome-bob-the-builder.pages.dev shows high-risk / scam indicators.
This assessment found strong scam indicators. Do not pay, sign in, or share personal details with this site.
| What this site appears to be | Short landing/login-style page for 'ShareFile Pro' claiming secure, end-to-end encrypted file sharing with zero-knowledge. Lacks forms, pricing, contact, or verifiable trust/legal information. |
|---|
Evidence status and limitations
Evidence completeness: UNKNOWN
- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.
At a glance
The checks that decide most of this verdict.
| Malware engines | 5 flagged itVirusTotal | Risk |
|---|---|---|
| Google Safe Browsing | Not listedGoogle | Clear |
| Abuse reports on the host | 0 reportsAbuseIPDB; shared hosting inflates this count | Noted |
| Domain age | Not availableNo registration record was returned | Noted |
| Web archive | Never archivedNo public history of this site | Watch |
| Certificate | Encrypted connectionIssued by YE2 | Noted |
The page as captured
Key findings
- Automated classification: Sensitive Interaction Risk.
- At least one reputation service TrustSniffer consulted had flagged this domain at assessment time.
- The operator behind the site could not be independently connected to a real-world brand or person.
Full analysis
Security Alert
Fortinet, Sophos flagged this site in external intelligence checks, indicating elevated compromise/scam exposure that requires immediate caution.
The website presents itself as “ShareFile Pro,” a minimal file-sharing landing or login surface claiming simplified, end-to-end encrypted, zero-knowledge file sharing. Its apparent purpose is to attract users to a secure file-transfer service, but the available page provides insufficient detail to establish the operator, service mechanics, or commercial model.
Scam/Impersonation Risk
The site presents a material sensitive-interaction risk. External reputation checks recorded five malicious detections, one suspicious detection, and a confirmed blacklist result from multiple sources. These findings converge with the homepage’s unusually thin content: it makes high-stakes security claims—“End-to-end encrypted” and “Zero knowledge”—without explaining the product, encryption implementation, service ownership, or operational safeguards. The page is login-oriented in presentation but provides no established service context, creating a significant risk that credentials or confidential files could be submitted to an unverified destination. No distinct legal-entity identity contradiction or confirmed brand impersonation was observed in the supplied page evidence.
- The homepage is titled “ShareFile Pro” and displays the claims “Secure file sharing, simplified” and “End-to-end encrypted · Zero knowledge.”
- External reputation results recorded 5 malicious detections and 1 suspicious detection, with a confirmed blacklist result.
- The homepage contains no clear product detail, pricing, contact information, or verifiable trust information despite presenting a security-sensitive service.
Regulatory Verification Notes
The site’s regulatory and identity position cannot be established from the available content. No operator name, legal entity, licensing statement, registration number, governing jurisdiction, terms, privacy disclosure, or other verifiable corporate information is presented on the available page. This is a significant transparency gap for a service inviting the handling of potentially confidential files, although the absence of a disclosed license is a verification issue rather than independent proof of criminal conduct. Independent identity verification is also unresolved, and the site’s low external authority provides no meaningful support for its security claims. No broker-dataset match was identified.
- The homepage provides no operator, corporate, licensing, jurisdiction, terms, or privacy disclosure.
- No pricing, service limitations, or transactional model is visible on the homepage.
- The available authority signal is low and does not independently validate the business or its security claims.
What to Verify Next
Before any sensitive interaction, an organization should identify the service operator through an independently obtained corporate name and verify that entity through the relevant official registry. Any claimed encryption, zero-knowledge architecture, data-retention policy, and incident-contact process should be documented and technically corroborated through independent sources. Official support and contact channels should be confirmed through an offline or independently sourced route, and organizational policy should prohibit credential, confidential-file, or payment submission until those checks are complete.
- The homepage presents security claims without technical documentation or supporting governance material.
- The available page does not establish an accountable operator or formal service terms.
- No independent contact, support, or escalation route is documented on the available page.
Summary Verdict
The website has a critical trust posture and should be treated as an unverified, high-risk destination for sensitive interaction. The combination of confirmed external threat detections, a blacklist result, thin claim-supported content, and unresolved operator identity does not support normal account, credential, confidential-file, or financial use.
Infrastructure Integrity
The site is served through Cloudflare CDN/WAF infrastructure, which can mitigate direct exposure of hosting systems but is only a protective delivery layer and does not establish legitimacy. The observed infrastructure includes CDN edge servers and a potential origin candidate; this architecture neither validates the operator nor offsets the adverse reputation findings.
- Served from AS13335, CLOUDFLARENET — Cloudflare, Inc., US.
- Observed Cloudflare edge IPs include 104.18.20.135, 104.18.21.135, 104.21.11.97, and 104.21.37.214.
- The transport certificate is issued by YE2, uses Domain Validation (DV), and is valid to 2026-11-14T08:21:38+00:00.
Closing Assessment
Sensitive use should be withheld unless independent operator, service-security, and contact-channel checks produce satisfactory evidence; any required assessment should remain limited to non-sensitive observation.
Written analysis generated 2026-09-19 by the TrustSniffer Analysis Engine from the evidence in this report.
What the analysis found
2 findings contributed to this verdict, raised by page content, registration and ownership, analysis engine.
01 Governance Risk
- The page presents a sign-in form, and the operator behind it could not be independently verified.Page content
rule:PAGE_TYPE_LOGIN_UNVERIFIED - The public registration record for this domain is incomplete.Registration and ownership
rule:KF_WHOIS_INCOMPLETE
02 Sensitive Interaction Risk
- The analysis matched a pattern TrustSniffer treats as a direct threat to a visitor.Analysis engine
signal:direct_threat
Identity verification
| Status | UNVERIFIED |
|---|---|
| Identity score | 30/100 |
| Identity verification confidence | 50% |
- No on-site identity signals detected
Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence.
What TrustSniffer observed
First-party facts recorded during the assessment of weroll-byte-welcome-bob-the-builder.pages.dev.
- The request stayed on weroll-byte-welcome-bob-the-builder.pages.dev. It was not redirected to another domain. Clear
- It is hosted on CLOUDFLARENET, from a server in US. Noted
Domain intelligence
| Registrar | Not available |
|---|---|
| Hosting | CLOUDFLARENET - Cloudflare, Inc., US |
| Country | US |
| Server IP | 2606:4700:310c::ac42:2c68 |
| Name servers | Not available |
| SSL issuer | YE2 |
| SSL expiry | 2026-11-14 |
| Domain age | Not available (no registration date was returned) |
| Domain expiry | Not available |
| Archive first seen | Not available |
| Archive snapshots | 0 |
| Reputation | VirusTotal: 5 flagged | AbuseIPDB: 0 reports | Google Safe Browsing: 0 matches |
About this assessment
A trust score summarises the evidence TrustSniffer could collect about weroll-byte-welcome-bob-the-builder.pages.dev at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.
TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.