ftp[.]comdubaibooking[.]webflow[.]io
“ftp.comdubaibooking.webflow.io”
Observation enregistrée
Contraste de titres observé
Résumé des preuves
Analysis of ftp.comdubaibooking.webflow.io, first observed on June 12 2026, indicates that the site is being leveraged for generic phishing. The domain is hosted on Webflow’s infrastructure, a legitimate website‑building service, which allows threat actors to obtain sub‑domains with minimal registration friction. VirusTotal scans have returned three positive detections out of ninety‑one submitted security engines, confirming that at least a minority of AV products recognize malicious behavior associated with the host. Independent blocklist providers have added the domain to their feeds; PhishDestroy currently lists it as blocked, and one additional security blocklist references the address.
No public Safe Browsing verdict, OTX entry, or SSL certificate details are available in the open‑source record, and the page title or content has not been captured by automated crawlers. Consequently, the full scope of the phishing campaign—such as targeted brand, credential‑stealing forms, or victim geography—remains unknown. Defenders should treat the domain as hostile. Network‑level controls ought to deny outbound HTTP/HTTPS requests to the host, and DNS filtering should include the domain in deny‑list policies.
Security information and event management (SIEM) rules can be tuned to alert on any connection attempts to the IP ranges used by Webflow, especially when paired with user agents indicative of credential‑submission. Incident response teams should advise end users to disregard any unsolicited communications that reference “Dubai booking” or similar terms, as the domain appears crafted to exploit travel‑related expectations. Continuous monitoring of VirusTotal, PhishDestroy, and other blocklist feeds is recommended to capture any changes in detection counts or additional attribution. Until further forensic evidence is gathered, the domain should remain classified as an elevated‑risk phishing host and be blocked across enterprise security controls.
Data Coverage
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
État du domaine
Accessible → Inaccessible
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif