Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
shares-usor[.]com
“U.S Oil ($USO) - Tokenising Real World Oil using Ledger Blockchain”
Сводка доказательств
The domain shares-usor.com is a phishing site engaged in brand impersonation, specifically targeting users of the cryptocurrency platform 'across'. This site poses a threat by attempting to deceive victims through a wallet-connect phishing scam, tricking them into connecting their crypto wallets under the guise of tokenizing real-world oil assets. As of the latest verification, shares-usor.com has been taken offline, but it previously operated as an active phishing domain.
Technical indicators for shares-usor.com show 0 of 95 VirusTotal vendors flagged the domain, and Google Safe Browsing did not detect it as malicious. However, the domain appears on 3 security blocklists, including PhishDestroy, MetaMask, and SEAL. It was registered through Hello Internet Corp on February 22, 2026, and resolved to the IP address 188.114.97.3, hosted by Cloudflare in the US. The SSL certificate was issued by Google Trust Services / WE1, and the observed page title was 'U.S Oil ($USO) - Tokenising Real World Oil using Ledger Blockchain'. Technologies detected include HSTS, Cloudflare, and HTTP/3, with nameservers lamar.ns.cloudflare.com and sky.ns.cloudflare.com.
Users who interacted with shares-usor.com should immediately revoke any token approvals granted to the site and transfer funds to a new wallet to prevent potential theft. If credentials were entered, change passwords for all associated accounts and enable two-factor authentication where possible. Report the phishing domain to platforms like MetaMask, PhishDestroy, or SEAL to aid in blocking future threats. Victims may also submit the domain to Google Safe Browsing and VirusTotal to improve detection.
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260222-3D5256- Заголовок сохранённой страницы
- U.S Oil ($USO) - Tokenising Real World Oil using Ledger Blockchain
- PDF-файл
- PDF с доказательствами
Правовое основание
Полный текст доказательств
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 13.08.2026
8 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
-
Статус домена
Доступен → Недоступен
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
-
Статус домена
Недоступен → Доступен
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии
Выявлено 3 технологии с высокой уверенностью
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание