usormeme[.]lol
“USOR | Airdrop”
usormeme.lol — सामग्री अनुपलब्ध (HTTP 502). घोटाले का प्रकार: Crypto Scam. साक्ष्य सारांश: VirusTotal 2/93 (Gridinsoft, SOCRadar); URLQuery 1 alert; 1 external blocklist match (ScamSniffer); PhishDestroy score 58/100. रजिस्ट्रार: Eranet International.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain usormeme.lol was registered on 21 February 2026 through Eranet International Limited and is currently taken offline. DNS resolution points to 188.114.97.3, an IP address owned by Cloudflare (AS13335) and geolocated in the United States. The domain uses Cloudflare’s default nameservers bella.ns.cloudflare.com and maciej.ns.cloudflare.com and does not present an SSL certificate, indicating an unsecured HTTP service when it was active.
The site’s page title, "USOR | Airdrop," and the identified phishing kit label “Airdrop Scam” align with the reported crypto‑airdrop scam type. Gridinsoft assigned a trust score of 0 out of 100, reflecting a high likelihood of malicious intent. Two of ninety‑three VirusTotal scanners flagged the domain, and it is listed on two public blocklists, PhishDestroy and ScamSniffer, confirming external detection of the threat.
The elevated risk rating is consistent with the observed indicators. While the site is no longer reachable, defenders should continue to block the domain at DNS and network layers, monitor the associated Cloudflare IP for any re‑use in future campaigns, and update email and web filtering rules to catch references to the "USOR" or "Airdrop" terminology. Analysts should also note the lack of SSL and the use of generic Cloudflare nameservers as potential hallmarks for similar crypto‑airdrop scams, and consider adding the registrar Eranet International Limited to watchlists for rapid‑turnaround registrations associated with phishing infrastructure.
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | usormeme.lol |
phishing | Phishing Block |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
फॉरेंसिक इंटेलिजेंस
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
PD-20260124-210A72 Recipient: support@eranet.com, support@tnet.hk, info@todaynic.com क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।