⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
Detected by 6 security vendors. Exercise extreme caution — do not enter personal information or connect wallets. साइबर अपराध प्राधिकरणों के पास दर्ज कराने के लिए एक आधिकारिक एआई-संचालित शिकायत पत्र उत्पन्न करें।
REGISTRAR NEGLIGENCE · EGREGIOUS NiceNIC International Group Co., Limited was notified 5 months ago — the threat is still operational.
Why this matters — ICANN RAA §3.18 obligation

On PhishDestroy delivered an evidence-backed abuse report to abuse@nicenic.net,abuse@verisign-grs.com,compliance@icann.org with VirusTotal detections, urlscan capture, legal violations, and full screenshot evidence. More than 5 months later, the phishing infrastructure remains reachable .

Under ICANN RAA §3.18 accredited registrars are contractually obliged to “take reasonable and prompt steps to investigate and respond appropriately to any reports of abuse.” Silence beyond 24 hours after a documented notification with verifiable evidence is not a timing issue — it is a policy decision to let the operation continue. PhishDestroy\'s position: where a registrar fails to act on clear evidence, the registrar has aligned itself with the operator of the scheme and bears co-responsibility for downstream harm caused to victims from the moment of notification onward.

Elapsed since first report
5 months
Reports sent
1
Latest case ID
PD-20260220-EEDBC2
Current status
Serving traffic (alive)
rustbuffer.com favicon

rustbuffer[.]com

डोमेन सुरक्षा और खतरे की खुफिया रिपोर्ट

“Just a moment...”

6/91 VT Unverified Feb 20, 2026 Unavailable since Feb 27, 2026 1 Report Sent CDN + more
15 जोखिम स्कोर
स्थानीयकृत रिपोर्ट सारांश

rustbuffer.com: VirusTotal पर 6/91 पहचान। DNS, SSL, रजिस्ट्रार, ब्लॉकलिस्ट और खतरे के साक्ष्य देखें।

मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।

PhishDestroy AI
HIGH
Ref
0C47F628
Score
15/100
Engine
PD-4 Turbo
The domain rustbuffer[.]com is a generic phishing site designed to deceive users into disclosing sensitive information. It does not impersonate a specific brand or deploy a known crypto drainer kit. As of the latest verification, rustbuffer[.]com has been taken offline, reducing immediate risk to potential victims.

Technical indicators confirm rustbuffer[.]com as a phishing threat. The domain is flagged by 2 of 95 VirusTotal security vendors, including Fortinet and Gridinsoft, which assigned it a trust score of 1 out of 100. It appears on 1 security blocklist, PhishDestroy, and was registered through NiceNIC International Group Co., Limited on February 21, 2026. The site resolved to IP address 172.67.203.18, hosted by Cloudflare in the US, and lacked an SSL certificate. Observed page content displayed 'Just a moment...', and technologies detected included Cloudflare and HTTP/3.

Users who encountered rustbuffer[.]com should take immediate safety steps. If credentials were entered, change passwords for all affected accounts and enable two-factor authentication. Monitor accounts for unauthorized activity and report any suspected fraud to financial institutions. To report the phishing domain, submit it to platforms like Google Safe Browsing, PhishTank, or local cybersecurity authorities. Victims may also file complaints with the registrar, NiceNIC International Group Co., Limited, to support takedown efforts.
VirusTotal
वायरसटोटल
6 det.
URLScan
यूआरएलस्कैन
Gridinsoft
1/100
Observed status
Last known active
PhishDestroy
विनाश सूची
Listed
Reports Sent
1
डेटा कवरेज वायरसटोटल 6 / 91 यूआरएलक्वेरी no detections ओटीएक्स no pulses सीएफ रडार suspicious यूआरएलस्कैन report ready डीएनएस ब्लॉक none एसएसएल no cert कौन है not parsed Screenshot कैद नहीं हुआ चेन पुनर्निर्देशित करें not probed Gridinsoft 1/100
सुरक्षा संकेत
GS Gridinsoft Analysis 1 / 100
Hosting SSL Certificate DDoS Protection Cloudflare Browser Insights Blacklisted by Security Providers Young Domain
नेटवर्क सुरक्षा इंटेलिजेंस Registrar Integrity Alert
High-Risk Registrar NiceNIC
PhishDestroy audit found that over 90% of domains registered through NiceNIC are associated with illegal content. This registrar systematically ignores abuse reports and its primary clientele consists of CIS-region scam operators. We have not identified a single legitimate project hosted on this registrar.
NiceNIC Verdict Full Investigation

धमकी प्रतिक्रिया पाइपलाइन

Discovery
Checks
Reports
Availability
16/17
पूर्व-सक्रिय खोज एवं अवशोषण
धमकी निगल ली गई
1/1 ✓
धमकी निगल ली गई
rustbuffer.com पहचाना गया और पूर्ण विश्लेषण के लिए कतारबद्ध किया गया
Feb 20, 2026
Threat Intelligence Checks
URLScan.io Snapshot · Cloudflare Radar · Web Archive · VirusTotal · Google Safe Browsing · High-Risk Registrar: NiceNIC · Forensic Evidence Collected · Technical Analysis Recorded · Site Came Back Online · Cloudflare Radar Scan · Cloudflare Radar Scan · Content Observed Unavailable · Content Observed Unavailable
13/13 ✓
URLScan.io Snapshot
Submitted to urlscan.io — screenshot, DOM & HTTP transactions captured
Feb 20, 2026
क्लाउडफ्लेयर रडार
Scanned via क्लाउडफ्लेयर रडार — DNS, certificates & network data
Web Archive
Preserved in वेबैक मशीन — historical evidence archived
वायरसटोटल
6 / 91 vendors flagged on वायरसटोटल
Aug 01, 2026
गूगल सुरक्षित ब्राउज़िंग
Mar 03, 2026
High-Risk Registrar: NiceNIC
90%+ illegal content — registrar ignores abuse reports. Read our verdict
Forensic Evidence Collected
Stored evidence from URLScan.io, URLQuery, stored screenshot
Feb 20, 2026
Technical Analysis Recorded
The report contains stored technology or forensic-analysis results
Aug 01, 2026
Site Came Back Online
Domain is responding again — monitoring resumed
Aug 01, 2026
Cloudflare Radar Scan
Scanned via Cloudflare Radar — network analysis completed
Mar 07, 2026
Cloudflare Radar Scan
Scanned via Cloudflare Radar — network analysis completed
Mar 07, 2026
Content Observed Unavailable
Monitoring recorded an unavailable response (HTTP 403); the cause was not independently established
Feb 27, 2026
Content Observed Unavailable
Monitoring recorded an unavailable response (HTTP 403); the cause was not independently established
Feb 27, 2026
Notification Records
दुर्व्यवहार की रिपोर्ट भेजी गई
1/1 ✓
दुर्व्यवहार की रिपोर्ट भेजी गई
दुरुपयोग की रिपोर्ट रजिस्ट्रार को भेजी गई NiceNIC International Group Co., Limited, hosting provider, 1 abuse contact
abuse@nicenic.net
Feb 20, 2026
प्रकाशन और उपलब्धता
DestroyList Published · Availability Unverified
1/2
डिस्ट्रॉयलिस्ट प्रकाशित
Feb 20, 2026
Availability Unverified
The latest response is insufficient to classify current availability

सार्वजनिक ब्लॉकलिस्ट स्थिति

साक्ष्य संग्रह

Live Snapshot
2026-02-20 19:17 UTC
Malicious · 6/91 engines
Forensic screenshot of rustbuffer.com showing the phishing page layout
IP: 172.67.203.18
NiceNIC International Group Co., Limited
Page Title
Just a moment...

डोमेन इंटेलिजेंस

Domainrustbuffer.com
Registrar NiceNIC RU(RU) PhishDestroy Investigation
Abuse contactabuse@nicenic.net
IP Address 172.67.203.18 CDN
GeoUS San Francisco, US
NetworkASAS13335 · AS13335 Cloudflare, Inc.
Origin IP is hidden behind a CDN proxy. Reverse-IP on the edge IP returns unrelated tenants — origin discovery requires passive-DNS or CT cross-reference.
Elapsed Since First Report 7 days
What we count Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Last known active.
What each report contains Stored outgoing report records may reference evidence available at the time, such as vendor verdicts, registration data, hosting details, classifications, or screenshots. This page does not infer the exact payload delivered, receipt, acknowledgement, or action by a recipient.
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
पहली बार पता चलाFeb 20, 2026
Nameservers["celine.ns.cloudflare.com","clay.ns.cloudflare.com"]
Case IDPD-20260220-EEDBC2
ICANN निगरानी · शुल्क वसूला गया

ICANN को भुगतान मिल गया। जवाबदेही नहीं पहुँची।

इस gTLD के लिए, ऊपर दिया गया रजिस्ट्रार ICANN के साथ अनुबंध के तहत काम करता है। ICANN पंजीकरण, नवीनीकरण और हस्तांतरण से जुड़े वार्षिक, परिवर्तनीय और लेनदेन-आधारित शुल्क वसूलता है।

मान्यता: कमाई का ज़रिया। जवाबदेही: कृपया बाद में फिर देखें।

फिर जादू शुरू होता है: ICANN RAA §3.18 लिखता है, रजिस्ट्रार अपने ही ग्राहक आधार के भीतर दुरुपयोग की जाँच करता है, और पीड़ित मुफ़्त में सबूत देते हैं, जबकि हर स्तर किसी और के कदम उठाने का इंतज़ार करता है। अगर इससे पीड़ित अधिक सुरक्षित महसूस करते हैं, तो शानदार—चालान ने अपना काम कर दिया।

जवाबदेही पर व्यंग्यात्मक नोट कुछ भी अपने आप नहीं भेजा जाता।
तकनीकें · 3 identified
Cloudflare Browser Insights
Analytics RUM

Performance monitoring tool that measures website speed from real users.

www.cloudflare.com
क्लाउडफ्लेयर
CDN

Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.

www.cloudflare.com
HTTP/3
Miscellaneous

Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.

Detected via क्लाउडफ्लेयर रडार · Wappalyzer engine
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

6 / 91 security vendors flagged this domain
View on VT
alphaMountain.ai
CRDF
Forcepoint ThreatSeeker
Fortinet
Gridinsoft
सोफोस

संग्रहीत साक्ष्य

Wayback Machine Snapshot
A historical snapshot is available for evidence review
View Archive

साक्ष्य और बाहरी रिपोर्टें

क्या आप इस साइट से प्रभावित हुए?

आप अकेले नहीं हैं और इसमें शर्म की कोई बात नहीं है। ठग परिष्कृत अपराधी होते हैं जो विश्वास का दुरुपयोग करते हैं। अपने अनुभव की रिपोर्ट करना धोखाधड़ी के खिलाफ सबसे शक्तिशाली हथियार है — आपकी रिपोर्ट दूसरों को शिकार बनने से रोक सकती है और कानून प्रवर्तन को कार्रवाई करने में मदद कर सकती है। चुप ठग का सबसे बड़ा फायदा है। इसे तोड़ो।

यदि आपने इस डोमेन के साथ इंटरैक्ट किया है, व्यक्तिगत जानकारी दर्ज की है, या क्रिप्टोकरेंसी वॉलेट जोड़ा है — तो तुरंत कार्रवाई करें। नीचे इस घटना की रिपोर्ट करने और खुद को सुरक्षित रखने में आपकी मदद करने के लिए संसाधन दिए गए हैं।

रिकवरी ठगों से सावधान रहें! धोखाधड़ी का शिकार होने के बाद, अपराधी फिर से आपसे संपर्क कर सकते हैं और खुद को "रिकवरी एजेंट", वकील या जांचकर्ता बता सकते हैं, जो दावा करते हैं कि वे शुल्क लेकर आपके खोए हुए पैसे वापस ला सकते हैं। यह दूसरा घोटाला है। कोई भी वैध सेवा चोरी हुए क्रिप्टो को वापस पाने के लिए अग्रिम भुगतान नहीं मांगेगी। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

प्राप्त करने के लिए अपना देश चुनें आधिकारिक साइबर अपराध संपर्क, or एआई-संचालित शिकायत उत्पन्न करें →

अपना देश चुनें...
180+ देश
ज़ीरो-पीआईआई — आपका डेटा कभी ब्राउज़र से बाहर नहीं जाता। एआई आपकी भाषा में लिखता है

संबंधित डोमेन रिपोर्टें

xfi-com.xhost.live
xfi-com.xhost.live
23 detections · Similar title
trezordevices.io
trezordevices.io
22 detections · Similar title
legderhealth.com
legderhealth.com
22 detections · Similar title
trezordevicesupport.com
trezordevicesupport.com
22 detections · Unavailable · Similar title
instagramhelp.whf.bz
instagramhelp.whf.bz
21 detections
app.meopex.com
app.meopex.com
12 detections
gooddogshop.click
gooddogshop.click
22 detections
go.puotox.com
go.puotox.com
12 detections

Other Domains on 172.67.203.18 1 phishing domain

One other phishing domain shares this IP — possible co-located infrastructure

xlayaanid-paylternewz.tiaoxsid.my.id favicon xlayaanid-paylternewz.tiaoxsid.my.id 22/95

More Domains at NiceNIC 6 झंडे लगे

firelight-get.xyz favicon firelight-get.xyz 3/95 firelight-launch.xyz favicon firelight-launch.xyz 3/95 drop-flap.com favicon drop-flap.com 1/95 launch-firelight.xyz favicon launch-firelight.xyz 3/95 claim-fwa.fun favicon claim-fwa.fun 1/95 phase1-firelight.xyz favicon phase1-firelight.xyz 3/95

About This Report: rustbuffer.com

This report presents the latest stored evidence available to PhishDestroy. Source timestamps are shown where available; availability and vendor verdicts can change after collection.

The site displays a page titled “Just a moment...”.

rustbuffer.com has been flagged by 6 security vendors as of August 1, 2026.

यदि आपको लगता है कि यह सूची गलत है, तो आप अपील जमा करेंहमारी कार्यप्रणाली के बारे में अधिक जानकारी के लिए, हमारे अक्सर पूछे जाने वाले प्रश्न पृष्ठ.

किसी भी डोमेन की जाँच करें

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

अभी स्कैन करें

फ़िशिंग की रिपोर्ट करें

संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें

Report

सीधा खतरा फीड

Recent phishing reports and observed availability changes

Monitor

जानकारी में रहें, सुरक्षित रहें

लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।

सीधा खतरा फीड इस लिस्टिंग के खिलाफ अपील करें

पीड़ितों के लिए सिफारिशें और सलाह

एक अनुमानित $51 billion 2024 में अवैध क्रिप्टो वॉलेट्स में प्रवाहित हुआ (source). यदि आपने के साथ इंटरैक्ट किया था rustbuffer.com — अभी कार्रवाई करें।

मुझे तुरंत क्या करना चाहिए?
Urgent
  • टोकन अनुमोदन रद्द करें — use रद्द करें.कैश दुष्ट स्मार्ट कॉन्ट्रैक्ट्स को प्रदान की गई पहुँच हटाने के लिए
  • शेष निधि स्थानांतरित करें एक बिल्कुल नए वॉलेट में। समझौता किया गया वॉलेट अब सुरक्षित नहीं है।
  • सभी पासवर्ड बदलें — ईमेल, एक्सचेंज खाते, कुछ भी जो एक ही पासवर्ड साझा करता हो
  • 2FA सक्षम करें एक ऑथेंटिकेटर ऐप (एसएमएस नहीं) का उपयोग करें। एसएमएस-आधारित रिकवरी को अक्षम करें।
  • फ्रीज़ कार्ड्स यदि आपने फिशिंग साइट पर बैंकिंग विवरण दर्ज किए
मैं अपनी रिपोर्ट के लिए कौन सी जानकारी एकत्र करूँ?
एफबीआई दिशानिर्देश

के अनुसार FBI, सबसे महत्वपूर्ण विवरण लेनदेन डेटा हैं:

  • क्रिप्टोकरेंसी पते — ठग का बटुआ (जैसे, 0x5856...35985)
  • राशि और क्रिप्टो प्रकार — सटीक राशि (उदाहरण के लिए, 1.02345 ETH, 0.5 BTC, 500 USDT)
  • लेनदेन आईडी (हैश) — अनूठा ब्लॉकचेन लेनदेन पहचानकर्ता
  • सटीक तिथियाँ और समय — प्रत्येक लेनदेन और ठग के साथ पहली बातचीत का
  • Screenshots — घोटाला वेबसाइट, चैट संदेश, ईमेल, वॉलेट लेनदेन, सोशल मीडिया
  • सभी यूआरएल और डोमेन धोखेबाज़ द्वारा उपयोग किया गया (सहित rustbuffer.com)
  • Communications — ईमेल, टेक्स्ट संदेश, फोन नंबर, उपयोगकर्ता नाम जिनका उपयोग ठग ने किया

भले ही आपके पास सभी विवरण न हों — फिर भी रिपोर्ट दर्ज करें. आंशिक जानकारी अभी भी जांच में मदद करती है।

मुझे इस घोटाले की रिपोर्ट कहाँ करनी चाहिए?
  • एफबीआई आईसी3 — इंटरनेट अपराध शिकायत केंद्र (अमेरिकी संघीय रिपोर्टिंग)
  • Europol — यूरोपीय साइबर अपराध रिपोर्टिंग (ईयू)
  • चेनअब्यूज़ — एक्सचेंजों और प्लेटफार्मों पर स्कैम वॉलेट्स को चिह्नित करें
  • आपका क्रिप्टो एक्सचेंज — स्कैमर का पता फ्रीज करने के लिए Coinbase/Binance/Kraken सपोर्ट से संपर्क करें।
  • स्थानीय पुलिस — एक आधिकारिक रिकॉर्ड बनाता है, भले ही वे तुरंत कार्रवाई न कर सकें

एफबीआई ने बरामद किया 1 अरब डॉलर से अधिक पीड़ितों की रिपोर्टों की बदौलत 2024 में क्रिप्टो धोखाधड़ी में। आपकी रिपोर्ट मायने रखती है।

क्रिप्टो घोटाले आमतौर पर कैसे काम करते हैं?
  • नकली वेबसाइटें — थोड़े बदले हुए डोमेन के साथ वैध साइटों के पिक्सेल-परफेक्ट क्लोन
  • दुर्भावनापूर्ण अनुमोदन — "कनेक्ट वॉलेट" प्रॉम्प्ट्स जो हमलावरों को असीमित टोकन खर्च करने की अनुमति देते हैं
  • सूअर का वध — टेलीग्राम/व्हाट्सएप/डेटिंग ऐप्स के माध्यम से हफ्तों में बनाया गया भरोसा, फिर पैसे चोरी
  • रिकवरी घोटाले — नकली "रिकवरी एजेंट्स" द्वारा अग्रिम शुल्क की मांग कर पीड़ितों को फिर से निशाना बनाया जा रहा है। हमेशा एक घोटाला
  • नकली विज्ञापन और एयरड्रॉप — गूगल/सोशल मीडिया विज्ञापन और "मुफ्त टोकन" के ऑफ़र जो वॉलेट खाली कर देते हैं
  • एआई-संचालित धोखाधड़ियाँ — डीपफेक, स्वचालित फ़िशिंग, और एआई-जनित साइटें धोखाधड़ी का पता लगाना कठिन बना रही हैं
मैं भविष्य में खुद को कैसे सुरक्षित रख सकता हूँ?
  • हार्डवेयर वॉलेट का उपयोग करें (लेजर, ट्रेजर)। ब्राउज़र वॉलेट्स में कभी भी बड़ी मात्रा में धन न रखें।
  • आधिकारिक साइटों को बुकमार्क करें — ईमेल, डीएम, या विज्ञापनों में दिए गए लिंक पर कभी क्लिक न करें
  • हर स्वीकृति पढ़ें — हस्ताक्षर करने से पहले अनुमतियों की पुष्टि करें। असीमित अनुमोदनों को अस्वीकार करें।
  • डोमेन सत्यापित करें — की जाँच करें फिश नष्ट करो संवाद करने से पहले HTTPS, वर्तनी, डोमेन की आयु की जाँच करें।
  • "सच होने के लिए बहुत अच्छा" = घोटाला — गारंटीशुदा रिटर्न, सेलिब्रिटी समर्थन, तत्काल समय-सीमाएँ
क्रिप्टो घोटाले की समस्या कितनी बड़ी है?
  • $51 billion 2024 में अवैध क्रिप्टो वॉलेट्स में प्रवाहित हुआ — कॉइनलेजर
  • सूअर का वध नुकसान साल-दर-साल 40% बढ़ा, अब यह सबसे तेजी से बढ़ने वाला धोखाधड़ी का प्रकार है।
  • केवल ~5% पीड़ित रिपोर्ट करते हैं — आपकी रिपोर्ट आपराधिक नेटवर्क को बंद करने में मदद करती है
  • एफबीआई ने 1 अरब डॉलर से अधिक बरामद किए 2024 में पीड़ितों की रिपोर्टों की बदौलत — एफबीआई.gov

स्रोत: FBI · कॉइनलेजर · वर्ल्डमेट्रिक्स

एक अत्यंत सच्चा धन्यवाद-पत्र

व्यंग्यात्मक मसौदा जनरेटर

प्राप्तकर्ता
शुल्क संदर्भ

यह व्यंग्यात्मक मसौदा है। शुल्क के आंकड़े अनुमान हैं; इन्हें इस डोमेन से ठीक-ठीक जोड़ने का दावा नहीं किया जाता।

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।