bushids[.]onelink[.]me
“Échanger des skins CS2 (CS:GO) ⭐️ Meilleur site d'échange et skins CS2 (CS:GO) et robot d'échange …”
bushids.onelink.me — Não verificado. Representação da marca: Backpack; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 1/91 (Forcepoint ThreatSeeker); PhishDestroy score 63/100. Registrador: OneLink (Branch).
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, bushids.onelink.me, was registered on 2026-02-21 through the OneLink (Branch) URL-shortening service. DNS resolution points to 172.67.193.151, an address owned by Cloudflare (AS13335). The site presents a page titled “Échanger des skins CS2 (CS:GO) ⭐️ Meilleur site d'échange et skins CS2 (CS:GO) …”, which references a skin‑exchange service for CS2/CS:GO and aligns with the brand-impersonation campaign targeting the Backpack brand. HTTP requests return a 403 status, suggesting the host is restricting access or actively blocking requests. Infrastructure scoring from Gridinsoft assigns a trust rating of 0 / 100, indicating a high likelihood of malicious intent. The domain is listed on a single security blocklist and has been flagged by PhishDestroy. TLS is provided by a GTS CA 1P5 certificate, confirming standard HTTPS encryption but offering no indication of legitimacy. No public malware detections have been reported, and VirusTotal scans (93 vendors) have not flagged the domain, though the absence of detections does not confirm safety. Current evidence points to an active brand-impersonation operation that may use the short-link service to hide the final landing page and lure users into a fraudulent skin‑exchange workflow. Defenders should immediately block DNS resolution for bushids.onelink.me, add the address to network-level deny lists, and monitor for traffic to the associated Cloudflare IP. Additional scrutiny of any URLs generated through OneLink services is advised, as similar abuse patterns have been observed. Continuous re-evaluation is recommended as further content analysis becomes available.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo