MALICIOUS — HIGH
register-buttbear[.]fun
The domain register-buttbear.fun was registered on February 21, 2026 and is currently taken offline.
- VirusTotal
- 2/93
- Blocklists
- No stored match
- उपलब्धता
- सामग्री अनुपलब्ध · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
register-buttbear.fun — सामग्री अनुपलब्ध (HTTP 502). ब्रांड प्रतिरूपण: Solana; घोटाले का प्रकार: Crypto Scam. साक्ष्य सारांश: VirusTotal 2/93 (Gridinsoft, SOCRadar); PhishDestroy score 56/100.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Evidence Analysis
The domain register-buttbear.fun was registered on February 21, 2026 and is currently taken offline. Infrastructure analysis shows it resolves to the IP address 172.67.197.73, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. The site presented an SSL certificate identified as WE1, indicating a valid TLS layer was in place while the site was active. Page metadata revealed the title "BUTT BEAR | Airdrop," aligning with the known phishing kit classified as an Airdrop Scam that impersonates the Solana brand.
Reputation scoring from Gridinsoft assigned a trust score of 0 out of 100, reflecting a severely malicious profile. The domain has been added to at least one security blocklist and was actively blocked by the PhishDestroy mitigation service. VirusTotal scans recorded two detections out of ninety-three participating security vendors, confirming that multiple independent engines flagged the domain as malicious.
Although the site is now offline, defenders should continue to monitor the associated IP address for any resurgence of malicious activity, enforce blocklisting of the domain and its IP in perimeter defenses, and ensure that any inbound traffic to Cloudflare‑owned ranges is inspected for similar brand‑impersonation patterns. Organizations that interact with Solana‑related services should educate users about unsolicited airdrop offers and enforce strict verification of URLs before providing credentials or wallet information. Ongoing threat‑intel feeds should be consulted for any re‑use of the same certificate fingerprint or page title in new campaigns, as the observed indicators suggest a reusable phishing kit targeting cryptocurrency communities.
डेटा कवरेज12 recorded checks
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
फॉरेंसिक इंटेलिजेंस
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टेंIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।