सुरक्षा रिपोर्ट पर जाएँ
Checked 09/08/2026 Ref 140605A1

MALICIOUS — HIGH

bubuff.onelink.me की फ़िशिंग और सुरक्षा जाँच

bubuff[.]onelink[.]me

The domain bubuff.onelink.me is a phishing site engaged in brand impersonation targeting users of the game CS2 (Counter-Strike 2).

63/100 evidence score · High
VirusTotal
1/91
Blocklists
No stored match
उपलब्धता
पहुंच योग्य · पहुंच प्रतिबंधित · HTTP 403
Report / Add Evidence Appeal this listing
2026-02-26 22:22 UTCपहुंच योग्य · पहुंच प्रतिबंधित · HTTP 403

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 1। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
Jump to section
रिपोर्ट सारांश

bubuff.onelink.me — पहुंच योग्य · पहुंच प्रतिबंधित (HTTP 403). ब्रांड प्रतिरूपण: Cs2; घोटाले का प्रकार: Generic Phishing. साक्ष्य सारांश: VirusTotal 1/91 (Forcepoint ThreatSeeker); PhishDestroy score 63/100. रजिस्ट्रार: OneLink (Branch).

मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।

Evidence Analysis

Ref 140605A1

The domain bubuff.onelink.me is a phishing site engaged in brand impersonation targeting users of the game CS2 (Counter-Strike 2). It poses as a skin trading platform, attempting to deceive victims through QR code hijacking (qr_hijack) to steal account credentials or other sensitive information. No crypto drainer kit was identified. As of the latest verification, bubuff.onelink.me has been taken offline, but its prior activity remains a confirmed threat.

Technical indicators for bubuff.onelink.me show 0 of 95 VirusTotal vendors flagged the domain as malicious, and Google Safe Browsing has not listed it. The domain appears on one security blocklist (PhishDestroy). It was registered through OneLink (Branch) on February 21, 2026, and resolves to the IP address 52.17.74.247, hosted on Amazon.com, Inc. infrastructure (AS16509) in Ireland. The SSL certificate is issued by GeoTrust RSA CN CA G2. The observed page title, 'CS日常事:官方解说公然调侃jabbi_BUFF163 skin trading platform,' further confirms its impersonation of CS2-related services.

Victims of bubuff.onelink.me should immediately change passwords for any accounts accessed or linked through the site, enable two-factor authentication (2FA) where available, and monitor accounts for unauthorized activity. If financial or crypto assets were exposed, revoke any token approvals and consider transferring funds to a new wallet. Report the phishing domain to platforms like Google Safe Browsing, PhishTank, or local cybersecurity authorities to aid in takedown efforts and prevent further harm.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
1 det.
URLScan
यूआरएलस्कैन
TLS प्रमाणपत्र
समाप्त या असत्यापित
आयु
6 mo
देखी गई स्थिति
पहुंच योग्य · पहुंच प्रतिबंधित 403
PhishDestroy
विनाश सूची
सूचीबद्ध
डेटा कवरेज12 recorded checks
VirusTotal 1 / 91 यूआरएलक्वेरी जाँच नहीं की गई फ़िशस्टैट्स जाँच नहीं की गई ओटीएक्स no community references सीएफ रडार no data URLScan capture संग्रहित रिपोर्ट URLScan verdict विश्लेषण पूरा हुआ डीएनएस ब्लॉक जाँच नहीं की गई TLS समाप्त या असत्यापित कौन है 6 mo old स्क्रीनशॉट 2 captures · 2 sources चेन पुनर्निर्देशित करें जांच नहीं की गई

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
10/12
धमकी निगल ली गई
bubuff.onelink.me पहचाना गया और पूर्ण विश्लेषण के लिए कतारबद्ध किया गया
26/02/2026
URLScan.io Capture
Stored URLScan report with capture artifacts
URLScan Verdict
यूआरएलस्कैन विश्लेषण पूरा हुआ; यह वेब-कैप्चर परिणाम पृष्ठ खतरे के फैसले को नहीं बदलता है · score 0
29/07/2026
VirusTotal
1/91 recorded on VirusTotal
05/08/2026
गूगल सुरक्षित ब्राउज़िंग
02/03/2026
Brand Impersonation
Impersonation of Cs2
Forensic Evidence Collected
Stored evidence from URLScan.io, stored screenshot
Technical Analysis Recorded
रिपोर्ट में संग्रहीत प्रौद्योगिकी या फोरेंसिक-विश्लेषण परिणाम शामिल हैं।
09/08/2026
Content Observed Unavailable
निगरानी ने एक अनुपलब्ध प्रतिक्रिया दर्ज की (HTTP 403); कारण स्वतंत्र रूप से स्थापित नहीं किया गया था।
02/03/2026
Complaint Draft Available
कोई सबमिशन दर्ज नहीं किया गया है. आप एक ड्राफ्ट बना सकते हैं, उसकी समीक्षा कर सकते हैं और उसे स्वयं उपयुक्त प्राधिकारी को सौंप सकते हैं।
डिस्ट्रॉयलिस्ट प्रकाशित
26/02/2026
Monitoring Continues
डोमेन पहुंच योग्य या पहुंच-प्रतिबंधित रहता है; भविष्य की जाँच इस अवलोकन को अद्यतन कर सकती है।

सार्वजनिक ब्लॉकलिस्ट स्थिति

सहेजा गया कैप्चर

डोमेन इंटेलिजेंस

डोमेन
URLScan Verdict विश्लेषण पूरा हुआ score 0 report ↗
सर्वर / ASN nginx/1.13.5 · AS16509 AMAZON-02, US
IP प्रतिष्ठा abuse score 0/100 0 reports checked 15/07/2026
Registrar (base domain) OneLink (Branch)
IP पता 52.17.74.247 IE
भौगोलिक स्थानIE Dublin, IE
नेटवर्कAS16509 · Amazon.com, Inc.
रिवर्स IPviewdns.info → rapiddns.io →
Registration (base domain)onelink.me · निर्मित 21/02/2026 (169d)
HTTP स्थिति403 Forbidden
Elapsed Since First Report 60 days
हम क्या मापते हैं Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: पहुंच योग्य · पहुंच प्रतिबंधित.
प्रत्येक रिपोर्ट में क्या शामिल है संग्रहीत आउटगोइंग-रिपोर्ट रिकॉर्ड उस समय उपलब्ध साक्ष्य का संदर्भ दे सकते हैं, जैसे विक्रेता के फैसले, पंजीकरण डेटा, होस्टिंग विवरण, वर्गीकरण, या स्क्रीनशॉट। यह पृष्ठ किसी प्राप्तकर्ता द्वारा वितरित सटीक पेलोड, रसीद, पावती या कार्रवाई का अनुमान नहीं लगाता है।
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
पहली बार पता चला26/02/2026
DOM Analysisanalyzed 23/04/2026score 63/1003 brand signals
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
Favicon Hash
पेज शीर्षक
CS日常事:官方解说公然调侃jabbi_BUFF163 skin trading platform
Impersonates
Cs2 Dota2 Steam
TLS प्रमाणपत्र
समाप्त या असत्यापित · जारीकर्ता GeoTrust RSA CN CA G2
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

1 / 91 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed First positive detection Previous stored snapshot: 0 detections
Forcepoint ThreatSeeker
साक्ष्य और बाहरी रिपोर्टेंIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें
इस रिपोर्ट को एम्बेड करेंRead-only HTML widget
HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/bubuff.onelink.me"
  title="PhishDestroy threat report for bubuff.onelink.me"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>