bimi[.]bookingcomsfdubaishopping[.]webflow[.]io
“bimi.bookingcomsfdubaishopping.webflow.io”
bimi.bookingcomsfdubaishopping.webflow.io — Contenido no disponible. Resumen de las pruebas: VirusTotal 1/91 (Fortinet); PhishDestroy score 55/100. Registrador: Webflow.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain bimi.bookingcomsfdubaishopping.webflow.io was registered through the Webflow platform on June 12, 2026. DNS resolution points to the address 172.64.151.8, which is owned by the Webflow hosting infrastructure. The domain is currently active and has been classified with an elevated risk rating. Automated scanning on VirusTotal shows that 1 of 91 security vendors flagged the domain, indicating the presence of at least one detection rule that matches known malicious patterns. In addition, the domain is listed on a single external blocklist, and the phishing‑specific feed PhishDestroy has already added it to its blocklist.
The available intelligence does not include a public page title, SSL certificate details, or HTTP response codes, so the content served by the site has not been captured in the current data set. Consequently, the exact phishing lure employed by the domain cannot be confirmed without further inspection of the live page. The limited detection footprint—only one vendor flag and a single blocklist entry—suggests that the malicious infrastructure may be newly deployed, which aligns with the recent registration date. Defenders should proactively block DNS resolution to 172.64.151.8 and add the full hostname to web filtering rules.
Network‑level egress controls that deny outbound connections to the Webflow hosting range can reduce exposure. Continuous monitoring of the domain’s reputation on VirusTotal and other sandbox services is advised, as additional detections may appear as more scanners analyze the site. Because the domain mimics the brand “booking.com” in its sub‑domain label, organizations that process genuine booking.com traffic should verify TLS certificate details and host header values to avoid false positives. Until the site’s payload is captured, the precise phishing technique remains uncertain, but the existing indicators warrant immediate mitigation.
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.