booking[.]com[.]sv2[.]cdnserveu555[.]homes
“Booking.com: Your details”
booking.com.sv2.cdnserveu555.homes — المحتوى غير متوفر. انتحال العلامة التجارية: Argent; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 10/93 (alphaMountain.ai, CRDF, CyRadar, Fortinet, G-Data); PhishDestroy score 85/100.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain booking.com.sv2.cdnserveu555.homes is currently listed as offline but exhibits multiple indicators of a brand‑impersonation campaign targeting the argent brand. Registration data shows the domain was created on 21 February 2026. DNS resolution points to the IPv4 address 72.11.147.146, which is hosted by HostPapa under autonomous system AS36352 and geolocated to Canada. The same IP address appears on a single security blocklist and has been actively blocked by the PhishDestroy service.
VirusTotal analysis reports that ten of ninety‑three scanning engines flagged the domain as malicious, providing additional corroboration of its fraudulent nature. The page title returned by the server reads “Booking.com: Your details”, confirming that the site is attempting to lure victims with a familiar travel‑booking brand while the underlying campaign claims to impersonate argent. Reputation services assign extremely low trust scores: Gridinsoft rates the domain at 0 out of 100 and Scamadviser at 1 out of 100, both indicating a high likelihood of abuse. The SSL certificate is identified only as “WE1”, which does not correspond to a recognized public‑trusted authority, further reducing confidence in the site’s legitimacy.
Although the site is presently taken offline, the observed infrastructure—specifically the use of a shared hosting provider, the low reputation metrics, and the presence on a blocklist—suggests that the domain was part of an active phishing operation. Defenders should continue to block the IP address and domain at network perimeters, add the domain to internal phishing blocklists, and monitor for any resurgence of the sub‑domain pattern. Additional investigation of any logged connections to 72.11.147.146 may reveal related malicious activity. Until a definitive takedown is confirmed, it is prudent to treat any communications referencing this domain as fraudulent.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب