bushids[.]onelink[.]me
“Échanger des skins CS2 (CS:GO) ⭐️ Meilleur site d'échange et skins CS2 (CS:GO) et robot d'échange …”
bushids.onelink.me — 未验证. 品牌冒充:Backpack; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 1/91 (Forcepoint ThreatSeeker); PhishDestroy score 63/100. 注册商: OneLink (Branch).
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, bushids.onelink.me, was registered on 2026-02-21 through the OneLink (Branch) URL-shortening service. DNS resolution points to 172.67.193.151, an address owned by Cloudflare (AS13335). The site presents a page titled “Échanger des skins CS2 (CS:GO) ⭐️ Meilleur site d'échange et skins CS2 (CS:GO) …”, which references a skin‑exchange service for CS2/CS:GO and aligns with the brand-impersonation campaign targeting the Backpack brand. HTTP requests return a 403 status, suggesting the host is restricting access or actively blocking requests. Infrastructure scoring from Gridinsoft assigns a trust rating of 0 / 100, indicating a high likelihood of malicious intent. The domain is listed on a single security blocklist and has been flagged by PhishDestroy. TLS is provided by a GTS CA 1P5 certificate, confirming standard HTTPS encryption but offering no indication of legitimacy. No public malware detections have been reported, and VirusTotal scans (93 vendors) have not flagged the domain, though the absence of detections does not confirm safety. Current evidence points to an active brand-impersonation operation that may use the short-link service to hide the final landing page and lure users into a fraudulent skin‑exchange workflow. Defenders should immediately block DNS resolution for bushids.onelink.me, add the address to network-level deny lists, and monitor for traffic to the associated Cloudflare IP. Additional scrutiny of any URLs generated through OneLink services is advised, as similar abuse patterns have been observed. Continuous re-evaluation is recommended as further content analysis becomes available.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。