Is 866jl.info safe?

http://866jl.info/

41/100
High Risk

Analysis coverage: strong · 3 of 5 core capabilities

Verdict

Deceptive F7MAX update prompt on a 109-day-old domain flagged by Gridinsoft as phishing.

The site displays a deceptive software update prompt for an app called F7MAX. A single antivirus engine flagged it as phishing. Avoid interacting with the update modal or downloading anything.

Read the full analysis
1 antivirus engine flagged this URLGridinsoft
Close the page immediately and do not interact with the update prompt or download any files.

01 · Investigation Brief

Investigation Brief

The page presents a modal overlay that urges visitors to install a software update for an application named F7MAX. Gridinsoft is the only engine among 92 that flagged the URL, specifically for phishing. The domain is only 109 days old and has no established traffic or reputation. The visual pattern matches common social-engineering tactics used to distribute unauthorized APK files. No contact information, business details, or legitimate content appear on the captured page. These signals together place the site in the suspicious category rather than a confirmed malicious verdict.

Why the score is 41

The score combines saved deterministic evidence with the grounded analysis available for this report. Coverage remains separate so missing sources cannot be mistaken for clean results.

02 · Security Evidence

Security evidence

Antivirus Engines

Saved result - stale

1 engine flagged this URL

Every saved adverse engine is listed below. The full provider matrix remains available for audit.

Malicious
1
Suspicious
0
Total
92
Adverse antivirus results
EngineFinding
GridinsoftMaliciousphishing
All 92 engine results
  • Gridinsoft - phishing - Malicious
  • 0xSI_f33d - unrated - Clean
  • Abusix - clean - Clean
  • Acronis - clean - Clean
  • ADMINUSLabs - clean - Clean
  • AILabs (MONITORAPP) - clean - Clean
  • AlienVault - clean - Clean
  • alphaMountain.ai - unrated - Clean
  • AlphaSOC - unrated - Clean
  • Antiy-AVL - clean - Clean
  • ArcSight Threat Intelligence - unrated - Clean
  • AutoShun - unrated - Clean
  • Bfore.Ai PreCrime - unrated - Clean
  • BitDefender - clean - Clean
  • Bkav - unrated - Clean
  • BlockList - clean - Clean
  • Blueliv - clean - Clean
  • Certego - clean - Clean
  • ChainPatrol - unrated - Clean
  • Chong Lua Dao - clean - Clean
  • CINS Army - clean - Clean
  • Cluster25 - unrated - Clean
  • CRDF - clean - Clean
  • Criminal IP - clean - Clean
  • CSIS Security Group - unrated - Clean
  • CTX AI - clean - Clean
  • Cyan - unrated - Clean
  • Cyble - clean - Clean
  • CyRadar - clean - Clean
  • desenmascara.me - clean - Clean
  • DNS8 - unrated - Clean
  • Dr.Web - clean - Clean
  • EmergingThreats - clean - Clean
  • Emsisoft - clean - Clean
  • Ermes - unrated - Clean
  • ESET - clean - Clean
  • ESTsecurity - clean - Clean
  • Forcepoint ThreatSeeker - unrated - Clean
  • Fortinet - clean - Clean
  • Fortra - unrated - Clean
  • G-Data - clean - Clean
  • GCP Abuse Intelligence - unrated - Clean
  • Google Safe Browsing - clean - Clean
  • GreenSnow - clean - Clean
  • GreyNoise - unrated - Clean
  • Guardpot - unrated - Clean
  • Heimdal Security - clean - Clean
  • Hunt.io Intelligence - unrated - Clean
  • IPsum - clean - Clean
  • Juniper Networks - clean - Clean
  • K7AntiVirus - unrated - Clean
  • Kaspersky - clean - Clean
  • LevelBlue - clean - Clean
  • Lionic - clean - Clean
  • Lumu - unrated - Clean
  • Malwared - clean - Clean
  • MalwarePatrol - clean - Clean
  • MalwareURL - unrated - Clean
  • Mimecast - unrated - Clean
  • Netcraft - unrated - Clean
  • OpenPhish - clean - Clean
  • PhishFort - unrated - Clean
  • Phishing Database - clean - Clean
  • Phishtank - clean - Clean
  • PREBYTES - clean - Clean
  • PrecisionSec - unrated - Clean
  • Quick Heal - clean - Clean
  • Quttera - clean - Clean
  • Rising - clean - Clean
  • SafeToOpen - unrated - Clean
  • Sangfor - clean - Clean
  • Sansec eComscan - unrated - Clean
  • Scantitan - clean - Clean
  • SCUMWARE.org - clean - Clean
  • Seclookup - clean - Clean
  • Snort IP sample list - unrated - Clean
  • SOCRadar - unrated - Clean
  • Sophos - clean - Clean
  • StopForumSpam - clean - Clean
  • Sucuri SiteCheck - clean - Clean
  • ThreatHive - clean - Clean
  • URLhaus - clean - Clean
  • URLQuery - unrated - Clean
  • Viettel Threat Intelligence - clean - Clean
  • VIPRE - unrated - Clean
  • ViriBack - clean - Clean
  • VX Vault - clean - Clean
  • Webroot - clean - Clean
  • Xcitium Verdict Cloud - clean - Clean
  • Yandex Safebrowsing - clean - Clean
  • ZeroCERT - clean - Clean
  • ZeroFox - unrated - Clean

Security Scans

Browser Threat Feed
Not flagged on major threat lists

Checked against the browser threat feeds available to this scan — no hit.

What we observed

Visual analysis

Visual warning signs were identified

The site displays a suspicious modal overlay masquerading as a software update notification for an application called 'F7MAX', which is a common tactic for social engineering and potentially malicious software distribution.

85/100 visual risk

What the captured page showed

4 observations
  1. 01

    Intrusive modal overlay prompting a software update for 'F7MAX'

  2. 02

    Use of urgency tactics via a 'New version found' notification to encourage user interaction

  3. 03

    Site content obscured by a dark background with a focus on an application update prompt

  4. 04

    Typical pattern of deceptive 'update' prompts often used to distribute unauthorized or malicious APK files

03 · Investigation Story

Investigation story

The behavior, reputation, and operator evidence that explains how this site may affect a visitor.
  1. 1

    What the site claims

    The page presents itself as a service operating on 866jl.info.

  2. 2

    What we observed

    The page content was captured and checked alongside 92 antivirus results.

  3. 3

    What independent research found

    No complete independent-research result was available in this saved report.

  4. 4

    What remains unverified

    2 of the five core capabilities did not complete, so those gaps remain visible in the coverage ledger.

malwareConfidence: Moderate

Scam-Type Likelihood

Scam-Type Likelihood

1 of 21 categories showed signals

Each card names a specific harm pattern and the concrete facts that support it. The category score is supporting context; the report verdict above remains the final severity decision.

Top match: Scareware & Fake Pop-ups
Scareware & Fake Pop-ups
Moderate likelihood
50/100
  • Tagged as scareware, abusive ads, or deceptive notification behavior.
20Show remaining categories
Malware15/100
PhishingNot detected
Investment ScamNot detected
Fake ShopNot detected
Tech Support ScamNot detected
Crypto FraudNot detected
Crypto Casino / Gambling ScamNot detected
Piracy Site — High-Risk AdsNot detected
Cracked Software — Malware RiskNot detected
Recovery / Refund ScamNot detected
Gaming ScamNot detected
Pig-Butchering / Romance-CryptoNot detected
Lottery / Prize ScamNot detected
Subscription TrapNot detected
Dropshipping / Low-Quality RetailNot detected
Deceptive Supplement FunnelNot detected
Brand ImpersonationNot detected
Fake Celebrity EndorsementNot detected
Fake GiveawayNot detected
Job / Task / Survey ScamNot detected

Reputation Sources

How this domain rates across independent threat-intelligence and blocklist providers.

Google Safe Browsing
Not listedCheck ↗
VirusTotal
ListedCheck ↗
AbuseIPDB
Not listedCheck ↗

04 · Domain & Infrastructure

Domain & infrastructure

Timeline · identity · encryption · redirects · hosting

The plumbing behind the site — who registered it, how it’s encrypted, where it’s hosted, and where it links out. A valid certificate or a calm server doesn’t mean the business is honest — scam sites pass these checks too. Use this to corroborate the verdict, not to overturn it.

Infrastructure map

How the saved page connected to the wider web.

Domain866jl.info
Redirects to866jl.info
Hosted byCloudflare, Inc.
Referencess1.kwai.net · cdn.adjust.com

Domain Timeline

  1. Apr 10, 2026
    Domain registered

    First appeared in WHOIS records — 4 months old today.

  2. Jul 28, 2026
    Saved security review — Flagged as suspicious

    The completed checks from this saved scan are detailed above.

866jl.info was registered very recently and is already flagged. Freshly-registered domains are disproportionately used for scams, and a young domain with active threat signals warrants extra caution.

Contact Verification

Saved contact details can help identify the operator. Their presence supports traceability; it does not prove the business is trustworthy.

What We Found
No clear contact details on the page
Emails on site's domainNone
Phone numbersNone
Postal addressNot listed
Linked social profiles0
Signal Summary
Several contact red flags
  • No direct contact email found on the captured page.

Domain & Encryption

Domain History
Age3 months old
RegistrarName.com, Inc.
RegisteredApr 10, 2026
ExpiresApr 10, 2027
Owner privacyUnknown
Encryption Certificate
StatusValid
ProtocolTLSv1.3
IssuerLet's Encrypt · YE2
ExpiresSep 6, 2026 (39d)
Self-signedNo
Hosting & Technology
HostingCloudflare, Inc.
Server locationUS
Web servercloudflare

Redirect Chain

Hops
1
Cross-domain
No
Lookalike
No
Punycode
No
  • 1301http://866jl.info/
  • 2200https://866jl.info/

Server Reputation

Abuse Intelligence
Confidence score0%
Reports on file0
ISPCloudflare, Inc.
Usage typeContent Delivery Network

Referenced Domains

Outbound domains this page links to or loads resources from. Each links to its own security scan.

05 · Evidence Ledger

Evidence ledger

Coverage, provenance, and source freshness remain separate so a missing check is never mistaken for a clean result.
Completed analysis

The conclusion is supported by the evidence saved with this report.

AntiviruspartialBrowser threat feedcompletePage contentcompleteAnalysiscompleteVisual evidencenot run

Technical threat

Malware, phishing, credential theft and hostile infrastructure.

suspicious

Antivirus warning needs confirmation

Operator / customer risk

Complaints, withdrawals, business conduct and commercial traps.

unknown

No confirmed evidence in this dimension.

Source coverage and freshness

Status shows whether usable evidence was saved; finding shows what that evidence observed.

Antivirus
Result: 1 of 92 engines flagged
Limited
Adverse
Freshness: stale fallback · Jul 28, 2026
Browser protection
Result: No browser threat-list match
Completed
No adverse finding
Page content
Result: Page fetched · HTTP 200
Completed
No adverse finding
Visual evidence
Result: 4 visible observations saved with the page capture
Limited
Adverse
Independent research
Result: Independent research was not available for this report
Unavailable
No saved finding

06 · Your Next Move

Your next move

Aggressive ads and redirects

Observed behavior includes unrelated pop-ups or redirects, notification prompts, or deceptive download controls. These are the primary risk unless the evidence separately proves a more serious mechanism.

  • Treat 866jl.info as unverified

    Do not enter credentials or send money until you have independently verified the business.

  • Close unexpected tabs and deny notification requests

    Do not follow an unrelated landing page, click "Allow notifications", or install a player, codec, browser extension, or update offered through an advert.

  • If you clicked "Allow", turn the notifications back off

    Open your browser's Site Settings → Notifications, find the site, and set it to Block (or remove it). That stops the spam pop-ups it now pushes to your desktop.

  • Remove anything installed through an advert

    Uninstall any browser extension, player, codec, or app added because of a pop-up, then run a reputable adware and malware scan. Do not call support numbers shown by unrelated landing pages.

    Open
Final verdictLevel 4 of 5
41/100 safety

High Risk

Deceptive F7MAX update prompt on a 109-day-old domain flagged by Gridinsoft as phishing.

The site displays a deceptive software update prompt for an app called F7MAX. A single antivirus engine flagged it as phishing. Avoid interacting with the update modal or downloading anything.

  1. 01

    Gridinsoft flagged the URL as phishing.

  2. 02

    Domain registered only 109 days ago with no established traffic.

  3. 03

    Page displays deceptive software-update modal for F7MAX.

Close the page immediately and do not interact with the update prompt or download any files.
Evidence balance8 signals
Positive
2
Limited
3
Risk
3
Analysis coverage
75%
strong coverage
Core capabilities
3/5
completed checks
Source coverage
2/5
sources complete
Evidence checks
2/8
completed checks flagged
Technical threatSUSPICIOUS55/100 risk
Operator / customer riskNot confirmed50/100 risk
Safety range

Saved evidence only. Missing checks are never treated as a clean result.

Scan another URL

07 · Community

Community

0 community contributions

Share what happened, what the site requested, and what others should watch for.

Community reviews never change the scanner verdict.

Loading…
Loading comments…

08 · Safety FAQ

Safety FAQ

Common questions, answered directly from the scan data above — so the answers reflect the saved verdict and evidence in this report.

Is 866jl.info a scam or a legit site?
866jl.info exposes visitors to aggressive advertising or malvertising behavior such as unrelated pop-ups, forced redirects, notification prompts, or deceptive download controls. 1 of 92 security engines flag it (1 as outright malicious). The external destination is a separate actor unless same-site evidence proves otherwise. Close unexpected tabs, deny notification requests, and do not install software offered through an advert.
Is 866jl.info safe to use?
866jl.info has a Safety Score of 41/100 (High Risk). Analysis coverage is strong at 75%. Avoid login, payment and downloads.
What is the risk from the ads and redirects on 866jl.info?
866jl.info can expose visitors to unrelated pop-ups, forced redirects, notification prompts, or deceptive download controls. Simply seeing an advert is not the same as an infection, but following the landing, allowing notifications, or installing an offered player, codec, extension, or update creates real risk. Close unexpected tabs, block notification permission, and scan anything you downloaded before opening it.
Why does 866jl.info open unrelated pages or pop-ups?
The saved browser evidence shows an aggressive advertising or affiliate path. A play, convert, continue, or download control may open a separate destination, and that landing can request notifications or offer unwanted software. This is malvertising exposure; it does not mean every message on the external page was written by 866jl.info.
How do I stop the pop-ups or notifications from 866jl.info?
If you're getting pop-ups even after closing the page, you probably clicked "Allow" on a notification prompt — the spam now comes from your browser, not the site. Open your browser settings → Site Settings → Notifications, find 866jl.info (and anything else you don't recognise), and set it to Block or remove it. Then uninstall any extension, "player", or app you added because of the page, and run a reputable free adware/malware cleaner (e.g. Malwarebytes) to clear leftover PUPs.
Has 866jl.info been flagged by antivirus engines?
Yes. 1 of 92 antivirus and blocklist engines in our malware network flagged 866jl.info, 1 of them as outright malicious. Even a single detection from a reputable engine is a meaningful warning, and multiple detections rarely happen by accident.
Is 866jl.info on any phishing or malware blacklists?
No — 866jl.info is not currently on the major browser blocklist feeds that Chrome, Safari, Firefox, and Edge rely on. Note that blocklists can lag behind brand-new scam domains, so "not listed" is reassuring but not a guarantee on its own.
How old is the 866jl.info domain?
866jl.info is 3 months old, registered on April 10, 2026 through Name.com, Inc.. Scam sites are very often freshly registered and short-lived, so an age under six months is a reason for extra caution.
Does 866jl.info have a valid SSL certificate?
Yes — 866jl.info presents a valid TLSv1.3 certificate issued by Let's Encrypt · YE2, valid for another 39 days. Important caveat: SSL only encrypts the connection between you and the site — it does not verify who runs it. Almost all scam sites now have valid SSL too, so a padlock alone never means "safe".
Where is 866jl.info hosted?
866jl.info resolves to an IP operated by Cloudflare, Inc. in US (Content Delivery Network). Hosting location alone doesn't make a site good or bad — but hosting that doesn't match a brand's claimed country, or that sits on networks known for abuse, is one of the many signals we weigh alongside the verdict above.
How often is the 866jl.info report updated?
This report is a record of the scan run on July 28, 2026, and the verdict reflects that point in time. Scam sites change fast — they can go live, get flagged, or vanish within days — so if you believe something about 866jl.info has changed, MalwareTips staff can run a fresh scan that re-checks every signal from scratch and republishes an updated verdict.