This company has verified ownership of the profile and can respond to reviews.
Verified Safe
Current checks include security-provider warnings. Review the detected warnings and supporting trust evidence before relying on the site.
Trust signal radarNormalized trust signals for dra.com.veDomain Maturity: 7407 daysDomain MaturityWarning Cleanliness: 2 detectionsWarningCleanlinessSafety Level: 0 negative tagsSafetyLevelPositive Signals: 4 positive signalsPositiveSignalsPopularity: Estimated low traffic without Tranco or social profile dataPopularityTrust Zone: .com.veTrust ZoneOperational Signals: 0 detected servicesOperationalSignalsLocation Credibility: Hosting country USLocation Credibility
Figure 1. Trust signal radar for dra.com.ve. Larger shaded area indicates stronger trust signals.
How we scored dra.com.ve
Tech signals:
Wordpress Platform, SEO Optimization, Extended Data
Positive signals:
a long-term domain history (20.3 years)
the domain owner has claimed this profile
an active SSL certificate (3 months)
extended data
Negative signals:
security-provider warnings
Last checked September 9, 2026 at 4:29 PM by
Gridinsoft Trust Model v2.5.3
Share this report?
Independent Gridinsoft analysis
What Gridinsoft observed on Dra.com.ve
A Gridinsoft threat analyst reviewed the site directly and documented the evidence behind this decision.
Current review
Review ID
GMA-20260824005900-81d1bb14
Reviewed
by Gridinsoft Threat Analyst
Analyst finding
Safe
Evidence basis
First-party site analysisExternal vendor intelligence: Contradictory context — not used for this decision
The independent current review supports Safe for dra.com.ve and its canonical www host. The historical incident was genuine: the exact ds5.txt URL served a functional Perl IRC bot from at least 2026-07-29 through public captures on 2026-08-15. It is no longer served. Current checks across four request profiles returned the normal HTTP 404 page at that exact path, and a complete crawl of all 128 current sitemap URLs found no malware delivery, unrelated redirect, injected page, credential theft, automatic download, or other exact harmful object. A fresh Gridinsoft rescan reached the live site but retained only the broad 2026-07-30 domain signature with positive_signals=[] and no current object-level basis. Current external blacklist labels are contradictory context, not evidence that the removed sample remains active. The broad Gridinsoft category therefore conflicts with the reproducible current state and should be removed. The documented hardening gaps warrant remediation but do not establish current malicious behavior. Safe describes the reviewed public deployment now, not its historical state or a guarantee against future compromise.
Analyst findings
Low1
Info4
Info01
The historical malware object was real and object-specific
Public scans and the archived response confirm that the exact ds5.txt path served a functional Perl IRC bot during the historical compromise. At the same time, the normal D’Empaire homepage remained separately reachable. This was a real malicious file at a specific URL, not merely a domain blacklist label and not proof that every page on the domain was malicious.
Info02
The exact malicious object is no longer served
The exact historical URL now consistently returns the normal D’Empaire HTTP 404 page across four request profiles. Later public urlscan records independently show the transition from HTTP 200 text/plain to HTTP 404, supporting removal rather than current delivery.
Info03
No current malicious public flow was reproduced
The complete current sitemap surface, apex/www redirect, forms, external resources, downloads, and request profiles remained coherent and same-site. The review found no current malware delivery, unrelated redirect, injected page, credential theft, automatic download, or exact harmful object.
Info04
Remaining domain labels are not a current malware sample
The fresh Gridinsoft report retained a broad domain signature without a current positive signal or exact current object. External vendor labels remain separately controlled reputation records; they do not demonstrate that the removed ds5.txt is still reachable or that current public pages exhibit malicious behavior.
Low05
Post-incident web hardening remains incomplete
The public site lacks common browser security-policy headers and exposes a Plesk login endpoint. Adding the applicable headers and restricting or strongly protecting administrative access would reduce future attack surface; the review did not reproduce an active exploit or unauthorized access.
Review 7 documented observations
View evidence
01Download
The exact previously reported object returned HTTP 404 with the normal D’Empaire Page not found HTML for desktop, mobile, Google crawler, and Gridinsoft review request profiles. All four responses had the same final URL and content, and none returned the former text file, a download, or an unrelated redirect.
HTTP status404
Final URLhttps://www.dra.com.ve/wp-content/languages/plugins/ds5.txt
MIME typetext/html; charset=UTF-8
Page elementAll four profiles returned the title Page not found : D’Empaire and the visible text Error 404, page not found.
02Navigation
A bounded crawl reviewed all 128 unique URLs in the current page, lawyer, and practice-area sitemaps. All final URLs remained on www.dra.com.ve; 127 returned HTTP 200 and the obsolete splash route returned the same normal HTTP 404 page. No reviewed page referenced ds5.txt, an executable or archive download, an unrelated final destination, an injected iframe, or a credential-collection flow.
Analyst observationThe current sitemap set contained 128 unique same-origin URLs; 127 returned HTTP 200 and one obsolete splash route returned HTTP 404.
Analyst observationEvery reviewed final URL used www.dra.com.ve, and no reviewed page referenced an executable, installer, archive, script package, mobile package, or ds5.txt download.
Page elementThe only iframe found was the expected Google reCAPTCHA fallback on the two same-origin contact pages; their forms posted to same-origin contact anchors.
Analyst observationThe reviewed external content hosts were limited to cdn.jsdelivr.net, Font Awesome, Google, Google Tag Manager, LinkedIn, gmpg.org, and the site itself.
03Redirect
The apex endpoint redirected once to the canonical https://www.dra.com.ve/ page, which returned HTTP 200. Cloudflare, Google, and Quad9 resolvers all returned the same address for the apex and www host. The active certificate covered both names and was valid through 2026-11-12.
HTTP status200
Redirect destinationhttps://www.dra.com.ve/
DNS factCloudflare, Google, and Quad9 each resolved dra.com.ve and www.dra.com.ve to 216.70.101.123 during the review.
Certificate factThe Let’s Encrypt certificate covered dra.com.ve and www.dra.com.ve and was valid from 2026-08-14 through 2026-11-12.
04HTTP response
A fresh supported Gridinsoft rescan reached the current site with HTTP 200 but retained the broad Suspicious Website signature dated 2026-07-30. The current report exposed an empty positive-signal list and named no exact current malicious URL, file, payload, redirect destination, exploit, command, or hash supporting that domain-wide category.
HTTP status200
Analyst observationThe fresh report returned positive_signals=[] for the current deployment.
Analyst observationThe retained domain signature was dated 2026-07-30 and contained no exact current malicious object or behavior trace.
05Historical content
Historical public evidence confirmed that the reported path was a real malicious object rather than a false alarm. Public urlscan records returned HTTP 200 and text/plain for this exact URL from 2026-07-29 through 2026-08-06. A Wayback capture from 2026-08-15 preserved a Perl ShellBOT that connected to an IRC command channel and implemented remote shell, download, port-scan, reverse-connection, mail, and UDP-flood functions. Later urlscan records on 2026-08-18 and 2026-08-21 returned HTTP 404.
Public artifact URLhttps://urlscan.io/result/019fae2b-4fcd-753c-9b67-8f8f33e81294/
Public artifact URLhttps://urlscan.io/result/019fd58e-bcbe-750f-bb3a-c5ea6a891a5f/
Public artifact URLhttps://urlscan.io/result/01a0157c-ea57-7499-be36-bf6116ad1c00/
Analyst observationThe archived 2026-08-15 response was 32,438 bytes of text/plain Perl source identifying itself as ShellBOT and exposing IRC-controlled remote administration and attack functions.
Analyst observationThe historical exact-object record and the current 404 state establish a time-bounded compromise and removal; they do not establish current domain-wide malicious behavior.
06Historical content
OTX listed two URLHaus-derived pulses for the exact www hostname and identified the ds5.txt URL, while its registrable-domain entry had no pulse. Public malware-feed indexes identified the preserved file as botnet malware. Separately, the current external domain snapshot still contained malicious or suspicious blacklist labels, but it named no currently reachable harmful path or current behavior trace. Public web indexes consistently associated the root domain with the long-established D’Empaire law firm.
Public artifact URLhttps://otx.alienvault.com/indicator/hostname/www.dra.com.ve
Public artifact URLhttps://otx.alienvault.com/indicator/domain/dra.com.ve
Analyst observationThe supplied VirusTotal URL identifier corresponds to http://www.dra.com.ve/, not to the historical ds5.txt object.
Analyst observationCurrent external domain results remained blacklist classifications and did not reproduce the removed exact object; external results were context only.
Analyst observationIndependent public legal directories and professional profiles consistently identified www.dra.com.ve as the website of D’Empaire, a Venezuelan law firm founded in 1972.
07Limitation
The current root response did not include HSTS, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, or Permissions-Policy headers, and plesk.dra.com.ve exposed the hosting control-panel login. These are current attack-surface and hardening concerns after a recent compromise, but no exploit, unauthorized login, injected content, or malicious response was reproduced.
Page elementThe reviewed root response exposed server and platform headers but none of the listed browser security-policy headers.
Final URLhttps://plesk.dra.com.ve:443/login.php
Analyst observationThe control-panel endpoint presented the expected Plesk login and was not authenticated, penetration-tested, or treated as evidence of compromise.
Scope and limitations
The verdict applies to the publicly reachable dra.com.ve, www.dra.com.ve, and exact reported ds5.txt path observed at the recorded time; it does not erase or contradict the confirmed historical compromise.
The review did not access the private server filesystem, database, Plesk account, WordPress administrator, source repository, deployment pipeline, backups, endpoint telemetry, or server logs, so the requester’s internal remediation measures were not independently audited.
The archived Perl file was reviewed statically and was not executed or allowed to contact its configured infrastructure.
No contact form was submitted and no administrative or authenticated function was exercised.
Public search, URL-scanning, sandbox, threat-intelligence, certificate, and archive indexes are incomplete. Authentication-gated API results that could not be retrieved were treated as unverified, not clean.
The public Plesk login was not penetration-tested. Its presence and the missing browser security-policy headers are hardening concerns, not proof of current compromise.
Safe describes observed current security behavior and does not guarantee future content, infrastructure integrity, or immunity from another compromise.
This domain was registered May 30, 2006 at 7:44 AM through the company NIC-VE
and had the owner Gridinsoft privacy protected.
Complaint contact not found.
About dra.com.ve
We reviewed dra.com.ve and found mostly positive signals. Current checks lean toward a legitimate, lower-risk profile, although a few caution points still keep it short of a fully verified standing. The current trust score is 89/100. Key signals include security-provider warnings and a domain age of 20.3 years. Verify key details before sharing personal information or relying on the site for important actions.
Figure 2.
Website screenshot for Dra.com.ve.
2026-09-09 19:29:51
FAQ
Is dra.com.ve safe?
Based on current analysis, dra.com.ve appears to be generally safe. The final verdict also reflects manual expert review. Basic verification is still reasonable before relying on the site.
Why does dra.com.ve look trustworthy?
Key factors include registrar information (NIC-VE) and hosting in US. The trust score blends security detections, domain and infrastructure signals, and on-page behavior patterns. Taken together, these factors support a mostly positive trust assessment, although routine verification is still reasonable.
Dra Digital Footprints
A structured view of the site's detected themes, page signals, and related online footprint elements.
Wordpress Platform
Our analyzer determines that this website is using WordPress CMS. WordPress is the most popular content management system, powering over 43% of websites globally.
Google Tag Manager
This website uses Google Tag Manager to add and update tracking tags on its website.
SEO Optimization
The dra.com.ve website employs search engine optimization (SEO) techniques to improve its visibility and ranking in search engine results pages (SERPs).
jQuery Library
Extended Data
This site includes extended structured page data about entities, offerings, or site metadata.
Long Term Domain
This site is registered for an extended period, which is generally a positive continuity signal.
Established Domain
dra.com.ve has maintained active domain presence over time, indicating operational continuity.
Claimed Company Profile
The company behind this site has claimed its profile in the Gridinsoft portal and provided verified ownership details.
External provider warnings: 2/26
This section shows what independent external security sources say about this site.
A warning appears when one or more sources report malware, phishing, abuse, or other safety concerns. Each row shows the source and its verdict.
If no source reports a warning, the site is shown as clear in this section.
CRDF
Malicious
Emsisoft
Malware
External provider results for Dra.com.ve, last checked September 9, 2026.
— VirusTotal
Domain Information
CreatedMay 30, 2006 at 7:44 AMUpdated: September 27, 2019 at 6:54 AM · Expires: June 29, 2027 at 9:00 PM
Domain Age20.3 years
RegistrantGridinsoft privacy protected
RegistrarNIC-VE
Top Level Domain.com.veDomain Extension
Technical Details
IP Address216.70.101.123
Hostnamedra.com.ve
Hosting ProviderAS398101 GoDaddy.com, LLCPhoenix, Arizona, US
SSL CertificateYR1TLS 1.3 · Valid for: 3 months · from September 4, 2026 at 2:56 PM · to December 3, 2026 at 2:56 PM
Name Serversns1.mediatemple.net ns2.mediatemple.net
Content Analysis
Website titleD’Empaire: Home
Website descriptionD'Empaire, a premier law firm in Venezuela, mergers and acquisitions, capital markets, finance and competition law.
If you own Dra.com.ve and want to challenge the trust score, please submit a review request via portal.gridinsoft.com. There you can claim your profile and add verified company/contact details. If you cannot access the portal, email legal(at)gridinsoft.com with proof of legitimacy and contact details. We never charge website owners for reviews or reconsideration requests. For more information, please review our Disclaimer.
A website report warns you. A PC scan protects you.
Unsafe sites can leave adware, unwanted apps, or hidden malware in downloads and browser settings. Run Gridinsoft Anti-Malware to check what may already be on this Windows PC.
Checks active threats, startup items, and suspicious downloads
Finds adware and unwanted apps linked to unsafe websites
Shows scan results before you decide what to remove
Your comment is currently undergoing moderation and will be published shortly.
Help protect others by sharing this page on social media! The more people who know about dra.com.ve, the fewer chances they have to deceive someone else.Help others evaluate dra.com.ve by sharing this page on social media!
Help protect others by sharing this page on social media! The more people who know about dra.com.ve, the fewer chances they have to deceive someone else. Help others evaluate dra.com.ve by sharing this page on social media!