0sl.io
Category: Phishing
Description of 0sl.io
0sl.io appears to be a technology website offering a URL-shortening service. Based on the homepage screenshot and visible navigation, the platform lets users shorten links and may provide related features such as UTM tagging, QR code generation, and password protection for shared links. The interface is presented primarily in Russian, with language switching options visible on the page.
The site appears to operate as a web-based utility rather than a content publisher or online store. Its branding, pricing page, account login area, and feature-focused homepage suggest a software or SaaS-style service intended for link management and sharing. Public WHOIS details indicate the domain is registered through REG.RU and hosted in Russia.
Safety Assessment for 0sl.io
Scan results are mixed at the classification level. On one hand, 0 out of 91 security engines detected malicious activity at the time of this scan, and major threat-database checks shown in the scan were clean. On the other hand, multiple web-classification providers categorized the domain as phishing or fraud-related, and one blacklist source listed the domain with a generic malicious-object label. The malware scan output also applied a generic heuristic label to the domain and its internal links, but these appear to be broad pattern-based findings rather than confirmed malware detections.
The website content visible in the screenshot looks like a functioning link-shortening platform rather than a parked page or obvious credential-harvesting clone. However, URL shorteners can sometimes be treated cautiously by reputation systems because they can obscure destination links, and that may contribute to adverse categorization even when direct malware detections are absent. The domain is more than a year old, uses valid HTTPS, and no threats were detected by the multi-engine malware scan at the time of review.
Based on available data, the strongest technical signals were clean at the time of this scan, but the phishing-related categorization by several classification sources suggests some caution may still be warranted.
Technical Description
The domain uses a valid Let's Encrypt SSL/TLS certificate that was active at the time of the scan, with certificate expiry listed as 2026-11-13. It resolves to IP address 37.143.14.193 and appears to be hosted by Internet-Hosting Ltd in Moscow, Russia. The nameservers are ns1.ihc.ru and ns2.ihc.ru.
DNSSEC is not enabled, which is still common but means DNS responses do not benefit from that additional integrity layer. The web server software and supported protocol details were not identified in the provided scan output. No direct malware-hosting evidence was detected by the multi-engine scan, though generic heuristic labels were applied to internal resources and one blacklist source recorded a listing at the time of this scan.
Share your experience with this website. Was it safe? Did you encounter any issues?