api[.]booking-dubaii-shopping[.]webflow[.]io
“api.booking-dubaii-shopping.webflow.io”
api.booking-dubaii-shopping.webflow.io — Контент недоступен. Сводка доказательств: VirusTotal 1/91 (Fortinet); CF Radar malicious; PhishDestroy score 55/100. Регистратор: Webflow.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain api.booking-dubaii-shopping.webflow.io was registered on June 12, 2026 through the Webflow platform. Automated analysis shows that the hostname resolves to the IP address 172.64.151.8, which is owned by Cloudflare’s network and commonly used for hosting static sites. The domain appears on a single security blocklist and has been flagged by the PhishDestroy service. VirusTotal has recorded a single positive detection out of 91 scanned vendors, indicating that at least one security product has identified malicious behavior associated with the host.
No additional public blocklists or safe‑browsing feeds currently list the domain, and no evidence of SSL/TLS certificates, HTTP response codes, or page title information is available in the intelligence set. Consequently, the precise content of the site, its payload, and the targeted brand cannot be confirmed at this time. The available indicators suggest that the domain is being used for a generic phishing campaign, consistent with the listed threat type. Defenders should consider adding the IP address 172.64.151.8 to network‑level deny lists, monitor DNS queries for the fully qualified domain name, and enforce existing phishing‑filtering rules that reference the PhishDestroy block.
Continuous re‑scanning with VirusTotal and other multi‑engine services is recommended to capture any changes in detection status. Organizations that employ Webflow‑based hosting should verify that the domain is not an authorized sub‑site of their own infrastructure. Until further evidence emerges, the domain should be treated as malicious and blocked in outbound and inbound traffic controls.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание