Suspicious Website
Gridinsoft currently classifies this site as Suspicious Website. The report highlights 7 blacklist detections, no established public user-review history, and phishing-related signals. These risks are driven by active warning signals despite the site's longer domain history.
Trust signal radarNormalized trust signals for all-z.coDomain Maturity: 875 daysDomain MaturityWarning Cleanliness: 7 detectionsWarningCleanlinessSafety Level: 5 negative tagsSafetyLevelPositive Signals: 1 positive signalsPositiveSignalsPopularity: Estimated low traffic without Tranco or social profile dataPopularityTrust Zone: .coTrust ZoneOperational Signals: 0 detected servicesOperationalSignalsLocation Credibility: Hosting country COLocation Credibility
Figure 1. Trust signal radar for all-z.co. Larger shaded area indicates stronger trust signals.
Negative signals:
security-provider warnings
multiple malware or phishing blacklist detections (7)
phishing-style impersonation signals
heuristic signals associated with phishing
limited independent reputation data
automated caution checks
limited public history
Positive signals:
a domain age of 2.4 years
Last checked August 26, 2026 at 11:55 PM by
Gridinsoft Trust Model v2.5.3
Share this report?
Independent Gridinsoft analysis
What Gridinsoft observed on All-z.co
A Gridinsoft threat analyst reviewed the site directly and documented the evidence behind this decision.
Current review
Review ID
GMA-20260826234846-0304a6d1
First-party site analysisExternal vendor intelligence: Context only — not used for this decision
The independent current review did not reproduce phishing or malware behavior on all-z.co. The fresh Gridinsoft scan named no harmful object, and all six exact short links surfaced by public indexes currently directed ordinary browser profiles only to official www.allianz.co PDF paths. No exact malicious URL, credential receiver, unrelated destination, executable, payload, or hash was identified behind the domain blacklist categories. The prior broad Phishing result is therefore unsupported and should be replaced by the narrower Suspicious Website classification. A domain-wide Safe conclusion is not warranted because the complete short-code namespace cannot be enumerated and known links hide their destinations from crawler, command-line, reviewer, and some mobile profiles. This result applies to the reviewed root and six known codes; future concerns require exact-link and destination-specific review.
Analyst findings
Low1
Info3
Info01
The broad Phishing result was not reproduced
The fresh Gridinsoft rescan and direct review did not identify a credential collector, impersonated login, unrelated harmful redirect, automatic executable delivery, malware file, payload, exploit, command, receiver, hash, or other concrete phishing object. The broad Phishing classification therefore exceeds the current reproducible first-party evidence.
Info02
All publicly identified exact links led to official Allianz documents
The six concrete short codes found in public URL intelligence and exact search were all reviewed. Ordinary browser profiles sent each one to a PDF path on www.allianz.co, and no checked object produced a credential form, unrelated destination, executable or archive download, malware payload, or harmful sample.
Low03
Short-link destinations are conditionally hidden from automated profiles
Known codes return their Allianz destination to ordinary desktop browsers and iPhone Safari, but return only OK without a Location header to Android Chrome, command-line, crawler, preview, and reviewer profiles. This behavior does not prove phishing, but it materially reduces transparency and prevents automated checks from observing the same destination as many users.
Info04
The complete redirect namespace requires exact-link review
The current evidence supports replacing the unsupported broad Phishing result with a narrower cautionary classification. It does not support a domain-wide Safe certification because active and future short codes cannot be completely enumerated and destinations are conditionally disclosed. Any harmful-content claim must be assessed against the exact short URL and destination.
Review 7 documented observations
View evidence
01HTTP response
A fresh supported Gridinsoft rescan completed for all-z.co. The root returned HTTP 404, the result exposed no positive behavior signal, and it did not identify an exact credential receiver, unrelated redirect, automatic download, malware file, payload, exploit, command, or hash. The pre-existing Phishing result remained attached to the broad domain signature rather than to a reproduced harmful object.
Public artifact URLhttps://gridinsoft.com/online-virus-scanner/url/all_z-co
HTTP status404
Page elementThe fresh result contained no positive behavior signal.
Analyst observationThe fresh result did not name a concrete harmful all-z.co URL, destination, file, payload, receiver, command, exploit, or hash.
02DNS
The apex resolved to two AWS Global Accelerator IPv4 addresses and served an empty HTTP 404 response over HTTPS. The www name did not resolve. The apex certificate covered only all-z.co and was valid from 2026-02-02 through 2027-03-03. A same-length nonexistent short code returned HTTP 404, while robots.txt, sitemap.xml, and favicon.ico returned bounded error text rather than a public directory or link-creation interface.
DNS factall-z.co resolved to 3.33.208.53 and 15.197.217.248; www.all-z.co did not resolve.
HTTP status404
Certificate factAmazon RSA 2048 M01 certificate for all-z.co, valid 2026-02-02 through 2027-03-03.
Analyst observationThe nonexistent short code /QQ00000 returned HTTP 404 and an explicit not-found response.
03Redirect
Every concrete short code surfaced by public URL intelligence or exact search was checked directly. The six distinct codes redirected ordinary desktop-browser profiles only to six PDF paths on the official www.allianz.co host. One code was also preserved inside an Allianz Colombia insurance document as the link to its general conditions. None of these exact samples redirected to an unrelated host, requested credentials, initiated an executable or archive download, or exposed a malware payload.
Analyst observationThe checked codes were /QQACEhJ, /QQzxgNi, /QQzxgMw, /QQzxfZq, /QQzxgQm, and /QQbg5AN.
04Redirect
The redirect service disclosed destinations selectively by user agent. Windows Chrome, Edge, Firefox, macOS Safari, and iPhone Safari profiles received the same HTTP 302 destination for the sampled code. Android Chrome, curl, Googlebot, Bingbot, Facebook preview, and Gridinsoft-review profiles instead received HTTP 200 with the two-byte body OK and no Location header. The same split was reproduced across all six known codes. This conditional destination suppression impedes automated object review, even though the destinations revealed to ordinary browser profiles were official Allianz documents.
Analyst observationWindows and macOS desktop browsers plus iPhone Safari received HTTP 302; Android Chrome, curl, crawler, preview, and reviewer profiles received HTTP 200 with body OK and no Location header.
Public OSINT for the exact host and its registrable parent referred to the same apex domain. urlscan returned no exact public scan. OTX returned zero pulses and seven URL observations: the root plus six short codes, all of which were checked directly. Wayback returned no snapshot. The current full public ThreatFox export, current URLhaus recent feed, and current OpenPhish feed contained no exact match. Exact public sandbox searches did not surface a sample-level result. Unavailable, authentication-only, and unindexed sources were treated as incomplete rather than clean.
Public artifact URLhttps://otx.alienvault.com/indicator/domain/all-z.co
Public artifact URLhttps://urlscan.io/domain/all-z.co
Public artifact URLhttps://web.archive.org/web/*/all-z.co/*
Analyst observationOTX returned zero pulses and seven URL observations; urlscan returned zero exact-host results; Wayback returned no record.
Analyst observationThe current full ThreatFox export, URLhaus recent feed, and OpenPhish feed contained no exact all-z.co host or URL match.
Analyst observationNo public result supplied an exact harmful URL, captured response, file, payload, credential receiver, hash, or sandbox behavior trace for all-z.co.
06Historical content
The current external snapshot reported 49 harmless, six malicious, one suspicious, and 34 undetected engines. The adverse entries were domain-level blacklist results from BitDefender, CyRadar, G-Data, Lionic, VIPRE, Webroot, and ESET; separate report providers also retained Avira, Norton, and Bitdefender warnings. None of the available entries identified the exact URL or sample whose behavior produced the category. They document current reputation disagreement, not a reproduced phishing object.
Analyst observationThe adverse entries were blacklist-method domain results and did not name an exact all-z.co URL, response, file, payload, receiver, or hash.
07Limitation
all-z.co is a short-link redirect namespace, not an ordinary website. The root exposes no directory, sitemap, public creation interface, or complete list of active codes. Six public exact objects were found and reviewed, but the complete current, deleted, private, and future short-code namespace cannot be independently enumerated. A clean finite sample therefore cannot certify every destination; any future abuse report must identify the exact short URL and its user-visible destination.
HTTP status404
Analyst observationNo public directory, sitemap, or link-creation interface was exposed by the reviewed root.
Analyst observationSix known codes were reviewed, but the complete short-code namespace was not publicly enumerable.
Scope and limitations
The exact submitted host is the registrable parent domain, so exact-host and parent-domain OSINT refer to the same all-z.co namespace; the nonexistent www alias was checked separately.
The review covered the fresh Gridinsoft result, the root, error paths, six public exact short codes, their current destinations, multiple browser and crawler profiles, DNS, TLS, public URL intelligence, threat-intelligence context, phishing feeds, sandbox search indexes, and archive availability.
The complete current, deleted, private, and future short-code namespace is not publicly enumerable. Six known public objects were reviewed, but no statement is made about unobserved codes.
Destination pages were checked through their redirect chains. Cloudflare challenged automated retrieval of the final PDF bodies, so the review relied on the exact official www.allianz.co destinations and independently indexed Allianz document context rather than claiming a full byte review of every PDF.
Conditional, geographic, account-bound, language-dependent, referrer-dependent, or time-limited destinations could differ outside the reviewed request profiles and locations.
Public search, urlscan, OTX, archive, feed, and sandbox indexes are finite. Absence from those indexes does not prove that no unindexed historical object ever existed.
Direct URLhaus and ThreatFox query APIs required authorization. Their current public export/feed files were checked separately, and unavailable interfaces were not treated as proof of safety.
External blacklist labels remain independently controlled context. They are not equivalent to a current reproducible malicious URL or sample and did not determine the Gridinsoft verdict.
The verdict does not certify every current or future short link as safe and is not a guarantee against later content or destination changes.
What is All-z?
All-z.co is evaluated here using its current reputation and technical signals. The report below separates risk findings, positive indicators, and contextual information.
Use caution with all-z.co. Its current Gridinsoft trust score is 1/100; review the site-specific findings below before use.
Why is all-z.co marked "Suspicious Website"?
Gridinsoft's current assessment of all-z.co is based on phishing indicators, automated caution checks, and heuristic signals associated with phishing. Context considered alongside those findings includes limited public traffic history. The listed status means the domain currently appears in Gridinsoft's own Threat List; it is not a consensus of external providers. 7 of 27 publicly displayed security sources report a warning. A separate license-restricted partner security signal also contributes to the automated assessment; its provider name and verdict cannot be displayed publicly under the source license.
A structured view of the site's detected themes, page signals, and related online footprint elements.
Long Term SSL Certificate
The SSL certificate for this site is valid for more than 6 months, indicating a long-term commitment to security and trust.
Listed by Gridinsoft
Gridinsoft Internet Security classified this site as unsafe. As a VirusTotal partner, our detections contribute to broader protection across tools and browsers.
Blacklisted by Security Providers
Security intelligence signal: A security-provider signal contributes to the automated assessment of all-z.co. Publicly displayable provider verdicts, when available, are reported separately; some source details may be restricted by license.
Phishing - High Risk
Automated analysis detected strong patterns on this site associated with phishing or brand impersonation. Exercise extreme caution and avoid entering passwords, verification codes, payment details, or personal information until legitimacy is independently confirmed.
If you own All-z.co and want to challenge the trust score, please submit a review request via portal.gridinsoft.com. There you can claim your profile and add verified company/contact details. If you cannot access the portal, email legal(at)gridinsoft.com with proof of legitimacy and contact details. We never charge website owners for reviews or reconsideration requests. For more information, please review our Disclaimer.
Leave a review
1
points /100
The score is based on a 1-100 scale, with 100 being the most reputable.
Check another website
Verify the security of domains and services based on 10M+ real websites.
Is This Your Website?
Think your website was scored unfairly? Request a reevaluation and our team will take another look.
A website report warns you. A PC scan protects you.
Unsafe sites can leave adware, unwanted apps, or hidden malware in downloads and browser settings. Run Gridinsoft Anti-Malware to check what may already be on this Windows PC.
Checks active threats, startup items, and suspicious downloads
Finds adware and unwanted apps linked to unsafe websites
Shows scan results before you decide what to remove
Your comment is currently undergoing moderation and will be published shortly.
Help protect others by sharing this page on social media! The more people who know about all-z.co, the fewer chances they have to deceive someone else.Help others evaluate all-z.co by sharing this page on social media!
Help protect others by sharing this page on social media! The more people who know about all-z.co, the fewer chances they have to deceive someone else. Help others evaluate all-z.co by sharing this page on social media!