MALICIOUS — HIGH
bubuff.onelink.me की फ़िशिंग और सुरक्षा जाँच
bubuff[.]
The domain bubuff.onelink.me is a phishing site engaged in brand impersonation targeting users of the game CS2 (Counter-Strike 2).
- VirusTotal
- 1/91
- Blocklists
- No stored match
- उपलब्धता
- पहुंच योग्य · पहुंच प्रतिबंधित · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
bubuff.onelink.me — पहुंच योग्य · पहुंच प्रतिबंधित (HTTP 403). ब्रांड प्रतिरूपण: Cs2; घोटाले का प्रकार: Generic Phishing. साक्ष्य सारांश: VirusTotal 1/91 (Forcepoint ThreatSeeker); PhishDestroy score 63/100. रजिस्ट्रार: OneLink (Branch).
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Evidence Analysis
The domain bubuff.onelink.me is a phishing site engaged in brand impersonation targeting users of the game CS2 (Counter-Strike 2). It poses as a skin trading platform, attempting to deceive victims through QR code hijacking (qr_hijack) to steal account credentials or other sensitive information. No crypto drainer kit was identified. As of the latest verification, bubuff.onelink.me has been taken offline, but its prior activity remains a confirmed threat.
Technical indicators for bubuff.onelink.me show 0 of 95 VirusTotal vendors flagged the domain as malicious, and Google Safe Browsing has not listed it. The domain appears on one security blocklist (PhishDestroy). It was registered through OneLink (Branch) on February 21, 2026, and resolves to the IP address 52.17.74.247, hosted on Amazon.com, Inc. infrastructure (AS16509) in Ireland. The SSL certificate is issued by GeoTrust RSA CN CA G2. The observed page title, 'CS日常事:官方解说公然调侃jabbi_BUFF163 skin trading platform,' further confirms its impersonation of CS2-related services.
Victims of bubuff.onelink.me should immediately change passwords for any accounts accessed or linked through the site, enable two-factor authentication (2FA) where available, and monitor accounts for unauthorized activity. If financial or crypto assets were exposed, revoke any token approvals and consider transferring funds to a new wallet. Report the phishing domain to platforms like Google Safe Browsing, PhishTank, or local cybersecurity authorities to aid in takedown efforts and prevent further harm.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
डेटा कवरेज12 recorded checks
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टेंIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।