dotabuff[.]at
Pemeriksaan phishing dan keamanan dotabuff.at
“Dotabuff - Dota 2 Analytics”
dotabuff.at — Terselubung · dapat dijangkau (HTTP 301). Jenis penipuan: Generic Phishing. Ringkasan bukti: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, ESET); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 99/100. Registrar: Hosting concepts.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Analysis of the domain dotabuff.at reveals a confirmed credential phishing operation targeting users of the legitimate Dota 2 analytics platform Dotabuff. The domain, registered on March 22, 2026, through Hosting Concepts B.V. via Registrar.eu, resolves to the IP address 188.114.97.3 and presents an exact replica of the authentic Dotabuff interface, as indicated by its page title 'Dotabuff - Dota 2 Analytics.' This mimicry is a common tactic to deceive users into entering login credentials or other sensitive information. Technical indicators strongly suggest malicious intent. The domain is flagged by 2 out of 95 security vendors on VirusTotal and appears on four distinct security blocklists, including SEAL, MetaMask, PhishDestroy, and BLP-Malware. Additionally, AlienVault OTX lists the domain in 23 threat intelligence pulses, further corroborating its association with malicious activity. Infrastructure analysis reveals the use of Cloudflare and Let's Encrypt SSL certificates, which are frequently leveraged by threat actors to obscure malicious traffic and lend a false sense of legitimacy to phishing sites. The presence of Cloudflare Browser Insights and HTTP/3 also aligns with techniques observed in other credential harvesting campaigns. The domain remains active as of July 12, 2026, and has not been remediated or taken down by its hosting provider. While the exact phishing kit or payload remains unconfirmed, the combination of domain spoofing, blocklist presence, and threat intelligence pulses leaves little doubt about its malicious purpose. Defenders should treat this domain as a high-risk indicator and prioritize blocking it at the network and endpoint levels. Organizations should also monitor for any authentication attempts originating from this domain, as compromised credentials may be used in subsequent attacks. Given the domain's recent registration and active status, continued vigilance is warranted.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Teknologi · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of dotabuff.at · checked Jul 12, 2026
Analisis Konfigurasi Situs
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive