bookiingcom-dubaei.webflow.io
“404 - Page not found”
bookiingcom-dubaei.webflow.io — Контент недоступен (HTTP 404). Олицетворение бренда: Unknown; Тип мошенничества: Impersonation. Сводка доказательств: VirusTotal 6/91 (ADMINUSLabs, alphaMountain.ai, CyRadar, Fortinet, Lionic); PhishDestroy score 68/100. Регистратор: Webflow.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Сводка доказательств
Analysis on July 29, 2026 confirms that the domain bookiingcom-dubaei.webflow.io is actively used for phishing. The site is hosted on the Webflow platform, as indicated by the registrar information stating registration through Webflow. DNS resolution points to the IPv4 address 172.64.151.8, which is part of the Fastly edge network commonly used for content delivery. The domain has been intercepted by the PhishDestroy mitigation service, which placed it on a phishing blocklist.
VirusTotal has recorded that six of ninety‑one scanning engines returned a malicious verdict, reinforcing the suspicion of abusive activity. Additionally, the domain appears on one external security blocklist, further corroborating its reputation as a threat vector. The available evidence does not reveal the specific landing page content, login form structure, or any SSL certificate details; these aspects remain unverified pending deeper content inspection. No Safe Browsing or Open Threat Exchange alerts are currently reported for this host, and no additional intelligence sources have published indicators beyond the listed blocklists.
Defenders should block all outbound and inbound traffic to bookiingcom-dubaei.webflow.io at the network perimeter, deny DNS resolution where possible, and add the IP address 172.64.151.8 to host‑based deny lists. Continuous monitoring of Webflow‑hosted subdomains for similar patterns is advised, as the platform can be leveraged to spin up new phishing sites rapidly. Organizations using email filtering should flag any messages that reference the domain or its sub‑resources, and security teams should update URL reputation feeds with the observed indicators to improve early detection.
Forensic History & Detection Timeline
-
Domain Status Transition Jul 29, 2026 · 07:00 UTCDomain state transitioned from alive to dead.
-
Threat First Observed Jul 29, 2026 · 06:44 UTCDomain ingestion complete. Initial state is marked as unknown pointing to IP
172.64.151.8.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Evasion analysis
Cloaking & traffic-distribution check
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not yet scanned
- Last cloaking scan
- Server header seen by scanner
cloudflare
Scanner note: dead_http: raw=http_404; http=404; via=https_proxy; server=cloudflare
Технологии · 2 identified
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of bookiingcom-dubaei.webflow.io · checked Jul 29, 2026
Сообщения сообщества
Сообщил 1 участник сообщества; впервые замечено 12.06.2026
- Сохранённые сообщения
- 1
- Уникальные URL
- 1
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание