events-usor[.]xyz
“U.S Oil | Airdrop”
events-usor.xyz — Konten tidak tersedia. Peniruan identitas merek: Across; Jenis penipuan: Wallet/seed Phishing. Ringkasan bukti: VirusTotal 4/93 (alphaMountain.ai, Gridinsoft, Seclookup, SOCRadar); 1 external blocklist match (ScamSniffer); PhishDestroy score 85/100. Registrar: Eranet International.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
events-usor.xyz is currently offline but its infrastructure indicates a deliberate brand‑impersonation campaign targeting the Across brand. The domain was registered on 21 February 2026 through Eranet International Limited and uses Cloudflare’s DNS service (david.ns.cloudflare.com, naya.ns.cloudflare.com). DNS resolution points to IP 188.114.97.3, which belongs to AS13335 Cloudflare, Inc., and is geolocated in the United States. No TLS certificate is presented, meaning the site would have been served over plain HTTP if it were active. The page title observed during the brief crawl was “U.S Oil | Airdrop”, and the underlying phishing kit has been identified as an “Airdrop Scam” commonly used for wallet or seed harvesting.
The campaign’s intent aligns with wallet/seed phishing, where victims are prompted to submit cryptocurrency wallet seeds or private keys. Threat‑intel feeds have already flagged the domain. It appears on two dedicated blocklists – PhishDestroy and ScamSniffer – and VirusTotal’s multi‑engine scan recorded four detections out of ninety‑three scanners. The lack of an SSL certificate and the use of a generic “U.S Oil | Airdrop” title suggest an attempt to lure users seeking cryptocurrency airdrops, a known vector for extracting private keys.
The domain’s short lifespan (registered less than five months ago) and immediate inclusion on blocklists indicate an opportunistic deployment. Uncertainty remains regarding the exact content of the landing page and any additional malicious payloads, as the site is presently taken offline and no further HTTP response data is available. Defenders should add the domain and its resolved IP address to deny‑list rules, monitor for any future resolution to the same IP or similar Cloudflare‑hosted nameservers, and continue to reference the identified phishing kit signature for detection. Ongoing observation of the associated blocklists and VirusTotal updates is recommended to capture any re‑activation attempts.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisis VirusTotal
Bukti & Laporan Eksternal
PD-20260124-C6FF22 Recipient: support@eranet.com, support@tnet.hk, info@todaynic.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive