bimi[.]bookingcomsfdubaishopping[.]webflow[.]io
“bimi.bookingcomsfdubaishopping.webflow.io”
bimi.bookingcomsfdubaishopping.webflow.io — Conteúdo indisponível. Resumo das evidências: VirusTotal 1/91 (Fortinet); PhishDestroy score 55/100. Registrador: Webflow.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain bimi.bookingcomsfdubaishopping.webflow.io was registered through the Webflow platform on June 12, 2026. DNS resolution points to the address 172.64.151.8, which is owned by the Webflow hosting infrastructure. The domain is currently active and has been classified with an elevated risk rating. Automated scanning on VirusTotal shows that 1 of 91 security vendors flagged the domain, indicating the presence of at least one detection rule that matches known malicious patterns. In addition, the domain is listed on a single external blocklist, and the phishing‑specific feed PhishDestroy has already added it to its blocklist.
The available intelligence does not include a public page title, SSL certificate details, or HTTP response codes, so the content served by the site has not been captured in the current data set. Consequently, the exact phishing lure employed by the domain cannot be confirmed without further inspection of the live page. The limited detection footprint—only one vendor flag and a single blocklist entry—suggests that the malicious infrastructure may be newly deployed, which aligns with the recent registration date. Defenders should proactively block DNS resolution to 172.64.151.8 and add the full hostname to web filtering rules.
Network‑level egress controls that deny outbound connections to the Webflow hosting range can reduce exposure. Continuous monitoring of the domain’s reputation on VirusTotal and other sandbox services is advised, as additional detections may appear as more scanners analyze the site. Because the domain mimics the brand “booking.com” in its sub‑domain label, organizations that process genuine booking.com traffic should verify TLS certificate details and host header values to avoid false positives. Until the site’s payload is captured, the precise phishing technique remains uncertain, but the existing indicators warrant immediate mitigation.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo