Highscore 46 · flagged Sunday, August 30, 2026

liajsjiq.lol

Appeared in the .lol zone on Sunday, August 30, 2026; by the end of that day the census found active website about crypto web3. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

TLD with a high abuse rate
matched: lol
+8
brand in page title, not in the name
matched: apple
+20
form on a brand-styled page
matched: has_form
+18
Registrar
Spaceship, Inc.
Nameserver provider
Nameservers
anuj.ns.cloudflare.com, gemma.ns.cloudflare.com
First-day state
active website
HTTP status
200
Page title
U Card - One Card, Global Access | USDT Instant Top-up Crypto Payment Card
Has a form
yes
Brand echoed

Model opinions

Second opinionlooks like a scamconfidence 72%· claude-opus-5

Randomly-generated .lol domain behind Cloudflare hosting a slick 'U Card' USDT-to-Visa/Mastercard crypto card offering with invented stats (50K+ users, 99.9% success), no corporate identity, licensing or offsite links, and a sign-up form posting to itself — the standard shape of an unlicensed crypto-card / fund-collection fraud. The 'Apple' hit is only 'Apple Pay' compatibility text, not brand impersonation.

First passlooks like a scamconfidence 85%· claude-haiku-4-5

The site presents itself as 'U Card', a cryptocurrency payment card service with its own branding and login form. The form posts to self with no offsite links (sealed-room phish pattern), but the page does not impersonate Apple, despite 'Apple Pay' mention in features. The domain liajsjiq.lol with .lol TLD, combined with a password form collecting credentials for an unverified crypto financial service, indicates a scam designed to steal login credentials or payment data rather than phishing a sp

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Sunday, August 30, 2026

Screenshot of liajsjiq.lol taken by the zone census on 2026-08-30

Same data as JSON: /api/zone/domain/liajsjiq.lol. This page is not indexed by search engines and does not link to the site it describes.