# PhishDestroy threat dossier — test.booking-com-dubaiuae-restaurants.webflow.io ================================================================ Fetched: 2026-06-26 18:04:28 UTC Canonical: https://phishdestroy.io/domain/test.booking-com-dubaiuae-restaurants.webflow.io/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 45/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- Registrar: Webflow Registered: 2026-06-12 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-12 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-12 22:30:30 UTC (by PhishDestroy tracker) First reported: 2026-06-15 00:27:29 UTC (abuse notice filed) Last verified: 2026-06-26 16:20:36 UTC Neutralised: 2026-06-13 00:14:22 UTC Current status: taken down (registrar suspended or DNS dead) ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-25 22:32:05 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] This domain, test.booking-com-dubaiuae-restaurants.webflow.io, is a phishing site impersonating Booking.com, a well-known travel and hospitality platform. The site likely targets users searching for restaurants or accommodations in Dubai, UAE, by presenting fake login pages or reservation forms. These pages are designed to harvest credentials, payment details, or personal information under the guise of legitimate Booking.com services. Users may be lured into entering sensitive data, which could then be used for fraud, identity theft, or unauthorized transactions. The inclusion of geographic terms like 'dubaiuae' in the domain suggests a targeted campaign aimed at users in that region. Analysis indicates this domain was registered on June 12, 2026, through Webflow, a platform commonly used for website hosting and development. As of the latest scan, the domain has not been flagged by any of the 95 security engines on VirusTotal, showing 0 detections. However, it appears on one security blocklist, suggesting that some systems have identified it as malicious. The domain is currently offline, which may indicate takedown action or temporary suspension by the hosting provider. The lack of detections on VirusTotal highlights the challenges in detecting new or low-prevalence phishing infrastructure, particularly when hosted on legitimate platforms like Webflow. If you visited this site or entered any information, take immediate action to secure your accounts. First, change the passwords for any accounts you may have accessed through the site, especially if you reused credentials. Enable multi-factor authentication where available to add an extra layer of security. Monitor your financial statements and credit reports for any unauthorized activity, as stolen payment details could be used for fraud. Consider reporting the incident to your local cybercrime unit or a relevant consumer protection agency. Avoid clicking on links in unsolicited emails or messages, and verify the legitimacy of any site claiming to be Booking.com by checking the official domain and looking for secure connection indicators (e.g., HTTPS). ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 7057f7b988a911ccaf232b947bde83cd ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/test.booking-com-dubaiuae-restaurants.webflow.io/ JSON API: https://api.destroy.tools/v1/check?domain=test.booking-com-dubaiuae-restaurants.webflow.io Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 170,568 domains (12,261 alive under monitoring, 157,919 confirmed takedowns/dead). Site: https://phishdestroy.io