ftp[.]comdubaibooking[.]webflow[.]io
“ftp.comdubaibooking.webflow.io”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
Kanıt özeti
Analysis of ftp.comdubaibooking.webflow.io, first observed on June 12 2026, indicates that the site is being leveraged for generic phishing. The domain is hosted on Webflow’s infrastructure, a legitimate website‑building service, which allows threat actors to obtain sub‑domains with minimal registration friction. VirusTotal scans have returned three positive detections out of ninety‑one submitted security engines, confirming that at least a minority of AV products recognize malicious behavior associated with the host. Independent blocklist providers have added the domain to their feeds; PhishDestroy currently lists it as blocked, and one additional security blocklist references the address.
No public Safe Browsing verdict, OTX entry, or SSL certificate details are available in the open‑source record, and the page title or content has not been captured by automated crawlers. Consequently, the full scope of the phishing campaign—such as targeted brand, credential‑stealing forms, or victim geography—remains unknown. Defenders should treat the domain as hostile. Network‑level controls ought to deny outbound HTTP/HTTPS requests to the host, and DNS filtering should include the domain in deny‑list policies.
Security information and event management (SIEM) rules can be tuned to alert on any connection attempts to the IP ranges used by Webflow, especially when paired with user agents indicative of credential‑submission. Incident response teams should advise end users to disregard any unsolicited communications that reference “Dubai booking” or similar terms, as the domain appears crafted to exploit travel‑related expectations. Continuous monitoring of VirusTotal, PhishDestroy, and other blocklist feeds is recommended to capture any changes in detection counts or additional attribution. Until further forensic evidence is gathered, the domain should remain classified as an elevated‑risk phishing host and be blocked across enterprise security controls.
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
Tespit zaman çizelgesi
-
Alan adı durumu
Erişilebilir → Erişilemiyor
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin