static[.]arabbooking-com-dubai-desert-safari[.]webflow[.]io
“static.arabbooking-com-dubai-desert-safari.webflow.io”
static.arabbooking-com-dubai-desert-safari.webflow.io — Inhalt nicht verfügbar. Zusammenfassung der Beweislage: VirusTotal 2/91 (Fortinet, Kaspersky); CF Radar malicious; PhishDestroy score 56/100. Registrar: Webflow.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
static.arabbooking-com-dubai-desert-safari.webflow.io is currently classified as an elevated‑risk generic phishing domain. The domain was registered on 12 June 2026 through the Webflow platform, which is commonly used for legitimate site hosting but can also be abused for malicious campaigns. DNS resolution points to the IP address 104.18.36.248, an address associated with Cloudflare’s content‑delivery network, indicating the use of a shared hosting service that may obscure the true operator. The domain appears on one security blocklist and has been specifically blocked by the PhishDestroy service, reinforcing the assessment of malicious intent.
VirusTotal scans show that two of ninety‑one antivirus or URL‑reputation engines flagged the domain, providing independent corroboration of suspicious activity. The domain is marked as active and listed with an elevated risk level, but no public page title, brand reference, or detailed payload analysis has been released, so the exact phishing lure (for example, credential harvesting for a travel‑booking service) remains uncertain. Because the hosted content has not been examined, the specific brand being impersonated or the credential‑collection mechanism cannot be confirmed.
Defenders should treat any traffic to this host as hostile, enforce network‑level blocking, and monitor outbound connections for attempts to contact the associated IP. Continuous re‑evaluation is advised, as further analysis of the hosted content could reveal additional indicators of compromise or targeted brands. Organizations should also consider updating web‑filter rules to include the full domain string, employing sandbox or URL‑reputation checks for any retrieved pages, and remaining alert to user‑reported attempts to access similarly named travel‑booking pages.
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
VirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt