The domain confirmbnb.online was registered on January 22, 2026 through Namecheap Inc and is currently delegated to the authoritative name servers dns1.registrar-servers.com and dns2.registrar-servers.com. DNS resolution points to the IPv4 address 75.2.60.5, an address that is not associated with any known legitimate service and is therefore a potential indicator of malicious hosting. The domain appears on a single public blocklist and has been actively listed by the PhishDestroy sinkhole, confirming that it is presently being used for malicious purposes.
VirusTotal records show that the domain was examined by 91 scanning engines, none of which reported a detection at the time of analysis; this lack of detection should not be interpreted as evidence of safety, as the content and behavior have not been publicly disclosed. No additional intelligence such as Safe Browsing status, Open Threat Exchange references, SSL certificate details, HTTP response codes, trust‑score metrics, or page‑title information is available, leaving the precise phishing payload and target brand undefined. Given the recent creation date, the use of a generic top‑level domain, and the presence on a known phishing blocklist, defenders should treat confirmbnb.online as a high‑confidence malicious indicator.
Recommended mitigations include adding the domain to network‑level deny lists, updating endpoint protection signatures to include the observed IP address, and monitoring for any outbound connections to 75.2.60.5. Continuous re‑evaluation is advised as additional telemetry becomes available, particularly any evidence of credential‑stealing pages or malware distribution tied to the domain.