Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is op_ct@cosmotown.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
mybnb[.]info
“Get Your 88% Off Airbnb Voucher”
mybnb.info — Non vérifié. Usurpation de l'identité de la marque : Airbnb; Type d'arnaque : Brand Impersonation. Résumé des preuves: VirusTotal 3/91 (Bfore.Ai PreCrime, Gridinsoft, SOCRadar); PhishDestroy score 71/100. Bureau d’enregistrement: TuringSign.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
The domain mybnb.info was registered on 21 March 2026 through TuringSign Inc. d/b/a Cosmotown. The registration is recent and coincides with the emergence of a generic_phishing campaign targeting users of short‑term rental platforms. The domain is currently active and listed under the threat type generic_phishing with a risk level of under_investigation.
Infrastructure analysis shows that mybnb.info resolves to the IPv4 address 194.145.208.24 and is hosted on the authoritative name servers ns11.knownsrv.com and ns12.knownsrv.com. No detections were reported on VirusTotal at the time of analysis (0/95), indicating that the payload or associated URLs have not yet been catalogued by public scanners. The IP address resides in a hosting range that is frequently used for short‑lived malicious sites, but no additional attribution can be derived from the limited data set.
The limited evidence suggests a typical phishing deployment that likely employs credential‑harvesting pages mimicking legitimate short‑term lodging services. However, the specific lures, credential collection mechanisms, and any secondary payloads remain unknown because no samples have been captured. The campaign’s short lifespan and recent creation date increase the difficulty of obtaining definitive indicators of compromise, leaving a degree of uncertainty around the full scope of the operation.
Defenders should proactively block resolution of mybnb.info at the network perimeter and monitor DNS queries for the associated name servers ns11.knownsrv.com and ns12.knownsrv.com. Continuous scanning of the IP 194.145.208.24 for outbound connections and HTTP activity is advised. Organizations that handle booking data should educate users about unsolicited requests for login information and enforce multi‑factor authentication to mitigate potential credential theft. Ongoing threat‑intel feeds should be queried for emerging indicators related to this domain.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 2 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org Confiance à 100 %OpenResty is a web platform based on nginx which can run Lua scripts using its LuaJIT engine.
openresty.org Confiance à 100 %Analyse VirusTotal
Données factuelles et rapports externes
PD-20260712-8CA9CB Recipient: op_ct@cosmotown.com Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif