log4j. properties
Domain named after a Java config file with minimal placeholder text and a single malware detection from Fortinet.
At a glance
Antivirus · registration · identity- 1 engine classified the URL as malicious and 1 as suspicious; 59 returned harmless, 31 returned undetected, and 0 returned no usable result.
- Operator identity: Missing. No independently verifiable operator identity
- The domain was registered Oct 24, 2015 and was 11 years old at scan time.
- Google Safe Browsing returned no listed threat categories for this address at scan time.
- The site presented a valid TLSv1.3 certificate at scan time.
Intelligence
The page loads a bare title and a single line of text inviting the visitor to click, with zero contact details, business information, or functional content. Fortinet flagged the page as malware while alphaMountain.ai marked it suspicious, even though the rest of our antivirus network and browser blocklists returned clean. The domain itself is over ten years old yet shows no traffic ranking, no search presence, and no evidence of ever operating as a legitimate site. Our research found zero scam reports or complaints, which is consistent with a low-traffic or unused domain rather than proof of safety. The combination of an odd filename-style domain, lack of any real business footprint, and the malware detection is enough to classify the site as suspicious.
Evidence Map
One or more reputation sources recorded a concern
No independently verifiable operator identity
No usable behavior observation was saved
The domain was registered Oct 24, 2015 and was 11 years old at scan time.
- 1Fortinet flagged the page as malware.
- 2Domain name exactly matches a common Java configuration file with no legitimate site attached.
- 3Page contains almost no content beyond a generic click prompt.
- 4Not indexed in global traffic rankings despite being registered for over a decade.
- 1Browser blocklist feeds returned clean.
- 2Hosting IP shows zero abuse reports.
- 3No scam reports or complaints found anywhere.
Page Content
The page contains only the title "log4j.properties" and the phrase "Click here to enter." No emails, phone numbers, addresses, login forms, or business details are present.
Infrastructure
Hosted on IP 103.224.182.246 with a valid Let's Encrypt certificate. The IP carries zero abuse reports. One engine (Fortinet) detected malware and another flagged it suspicious.
Domain History
Registered 3871 days ago through GoDaddy with no privacy protection. Despite the age, the domain has never appeared in search results as an active website or business.
Web Reputation
No scam reports, reviews, or business registrations were located. The name matches a standard Apache Log4j configuration file rather than any known company or service.
Web Research
log4j.properties is the standard name of a configuration file for the Apache Log4j Java logging library, used to set logging levels, appenders, and layouts.
The log4j.properties file sets the logging properties. You can modify the log4j.properties file to change the properties for the log4j loggers.
The default name of the log4j properties configuration file is log4j.properties. The Logger looks for this file name in the CLASSPATH.
Here are a few log4j.properties examples that are used in my project, just for sharing. 1. Output to Console All logging will be redirected to your console.
Put log4j.properties under WEB-INF\classes of the project as mentioned previously in this thread.
Threat Detection
Antivirus results, browser warnings, isolated page observations, and the threat pattern identified in this report.
Antivirus engine results
Evidence behind this threat profile
- 1Fortinet flagged the page as malware.
- 2Domain name exactly matches a common Java configuration file with no legitimate site attached.
- 3Page contains almost no content beyond a generic click prompt.
- 4Not indexed in global traffic rankings despite being registered for over a decade.
1 of 22 categories showed signals
This profile separates the site's primary threat from other patterns supported by the saved page evidence, public research, and security findings.
- Fortinet flagged the page as malware.
- Domain name exactly matches a common Java configuration file with no legitimate site attached.
- Page contains almost no content beyond a generic click prompt.
- Not indexed in global traffic rankings despite being registered for over a decade.
Technical Details
Identity, domain, infrastructure, and connection facts saved with this scan.
May 30, 2026 at 8:11 PM UTCIdentity
6 facts- Operator
- Missing
- On-domain email
- Not observed
- Other email
- Not observed
- Phone
- Not observed
- Postal address
- Not observed
- Social profiles
- Not observed
Domain
8 facts- Domain age
- 11 years old
- Registered
- Oct 24, 2015
- Registrar
- GoDaddy.com, LLC
- Expires
- Oct 24, 2026
- WHOIS updated
- Dec 8, 2025
- Registrant
- Unavailable
- Registration country
- Unavailable
- WHOIS privacy
- Not observed
Infrastructure
14 facts- HTTPS
- Valid certificate
- TLS protocol
- TLSv1.3
- Certificate issuer
- Let's Encrypt · R13
- Certificate subject
- whiteprice.it
- Certificate valid from
- Apr 30, 2026
- Certificate valid to
- Jul 29, 2026
- Network address
- 103.224.182.246
- ASN
- Unavailable
- Hosting organization
- Trellian Pty. Limited
- Country
- US
- Server
- Apache
- Site platform
- Unavailable
- IP reputation
- 0% confidence · 0 reports
- Tor exit node
- No
Connections
13 facts- Scan scope
- Domain
- Destination host
- log4j.properties
- Redirects
- 0
- Cross-domain redirect
- No
- Redirect status codes
- 404
- Lookalike characters
- Observed
- Internationalized domain
- No
- Page response
- 200
- Observation coverage
- Unavailable
- Extracted links
- Unavailable
- Unique IPs contacted
- Unavailable
- Countries contacted
- Unavailable
- Referenced domains
- 0
What to do
Do not visit or interact with the page. The combination of a misleading domain name and a malware detection makes it unsafe.
If you paid, contact your bank or payment provider immediately and preserve receipts and messages. If you shared personal information, monitor the affected accounts and change any reused passwords through the official service.
Final Verdict
Why this verdict
The address log4j.properties mimics the name of a common Java configuration file and shows almost no real website content. One security engine flagged it as malware while browser blocklists stayed clean and no scam reports exist. Treat it as untrustworthy and do not click or enter information.
Do not visit or interact with the page. The combination of a misleading domain name and a malware detection makes it unsafe.
Key evidence
- 1Fortinet flagged the page as malware.
- 2Domain name exactly matches a common Java configuration file with no legitimate site attached.
- 3Page contains almost no content beyond a generic click prompt.
Safety FAQ
Is log4j.properties safe to use?+
The address log4j.properties mimics the name of a common Java configuration file and shows almost no real website content. One security engine flagged it as malware while browser blocklists stayed clean and no scam reports exist. Treat it as untrustworthy and do not click or enter information.
What should I do about log4j.properties?+
Do not visit or interact with the page. The combination of a misleading domain name and a malware detection makes it unsafe.
How old is log4j.properties?+
log4j.properties is 11 years old and was registered oct 24, 2015.
What if I already interacted with log4j.properties?+
If you paid, contact your bank or payment provider immediately and preserve receipts and messages. If you shared personal information, monitor the affected accounts and change any reused passwords through the official service.
When was this report updated?+
This report reflects the scan completed May 30, 2026 at 8:11 PM UTC.
User reviews & comments(0)
Share your experience — "Lost $200 on a fake checkout" is more useful than "Scam". Your review helps others avoid traps.