confirmation63-booking[.]com
“Booking.com | Official website | Best hotels and accommodation”
Сводка доказательств
confirmation63-booking.com was registered on 7 November 2025 through Dominet (HK) Limited. The domain resolves to the Cloudflare address 172.67.159.70, which is associated with AS13335 in the United States. Nameservers listed are fattouche.ns.cloudflare.com and kristin.ns.cloudflare.com, indicating the use of Cloudflare’s DNS service. No TLS certificate is present, and the site is currently taken offline, returning no HTTP response. Public intelligence flags the domain as a banking‑phishing campaign targeting users of the travel booking brand referenced in the page title “Booking.com | Official website | Best hotels and accommodation.” The page title was captured before the takedown and matches the legitimate brand, suggesting a credential‑harvesting attempt.
The domain appears on one security blocklist and has been blocked by PhishDestroy. Google Safe Browsing classifies it under social engineering, and AlienVault OTX reports inclusion in two threat‑intelligence pulses. VirusTotal recorded 16 positive detections out of 95 scanning engines, reinforcing the malicious assessment. Reputation services assign extremely low trust scores: Scamadviser 1/100 and Gridinsoft 0/100. These scores, together with the observed detections, confirm a high‑risk profile.
Because the domain employs Cloudflare’s infrastructure, attribution to a specific operator is obscured, but the combination of registrar, recent creation date, and lack of SSL suggests a disposable phishing setup. Defenders should add the domain and its resolving IP to block lists, monitor for any re‑registration, and enforce email filtering rules that detect the brand‑related subject lines associated with this campaign. Continuous observation of Cloudflare‑owned IP ranges for anomalous traffic may help identify additional phishing sites that share the same infrastructure.
Data Coverage
Сигналы безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание