booking----tour--dubai[.]webflow[.]io[.]webflow[.]io
“booking----tour--dubai.webflow.io.webflow.io”
booking----tour--dubai.webflow.io.webflow.io — Контент недоступен. Сводка доказательств: VirusTotal 4/91 (alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, LevelBlue); PhishDestroy score 65/100. Регистратор: Webflow.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of booking----tour--dubai.webflow.io.webflow.io shows a newly registered Webflow sub‑domain created on 12 June 2026. The registrar information confirms the site was provisioned via the Webflow hosting service, which is frequently abused for short‑lived phishing infrastructure. VirusTotal has recorded 4 of 91 scanned security vendors flagging the domain as malicious, indicating that a minority of vendors have identified suspicious behavior, though the majority have not flagged it. The domain is listed on a single external security blocklist and is actively blocked by the PhishDestroy filtering service, providing additional evidence of malicious intent.
No public IP address, SSL certificate details, HTTP response codes, or Safe Browsing verdicts are currently available in the intelligence feed, limiting the ability to assess the underlying hosting environment or the presence of TLS encryption. The page title and any content‑level indicators have not been disclosed, so the specific lure or credential‑harvesting technique remains unknown. Given the combination of a recent creation date, a Webflow‑based sub‑domain, multi‑vendor detections, and inclusion on a phishing‑focused blocklist, the site should be treated as an elevated‑risk phishing resource.
Defenders should add the full domain to perimeter block lists, enforce URL filtering to deny outbound connections, and monitor DNS logs for queries to the domain. Incident response teams should also consider isolating any user‑initiated connections and reviewing recent authentication attempts for compromised credentials. Continuous re‑evaluation is advised as additional threat intel, such as host‑level analysis or page content extraction, may become available.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание