Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
mybnb[.]info
“Get Your 88% Off Airbnb Voucher”
Kanıt özeti
The domain mybnb.info was registered on 21 March 2026 through TuringSign Inc. d/b/a Cosmotown. The registration is recent and coincides with the emergence of a generic_phishing campaign targeting users of short‑term rental platforms. The domain is currently active and listed under the threat type generic_phishing with a risk level of under_investigation.
Infrastructure analysis shows that mybnb.info resolves to the IPv4 address 194.145.208.24 and is hosted on the authoritative name servers ns11.knownsrv.com and ns12.knownsrv.com. No detections were reported on VirusTotal at the time of analysis (0/95), indicating that the payload or associated URLs have not yet been catalogued by public scanners. The IP address resides in a hosting range that is frequently used for short‑lived malicious sites, but no additional attribution can be derived from the limited data set.
The limited evidence suggests a typical phishing deployment that likely employs credential‑harvesting pages mimicking legitimate short‑term lodging services. However, the specific lures, credential collection mechanisms, and any secondary payloads remain unknown because no samples have been captured. The campaign’s short lifespan and recent creation date increase the difficulty of obtaining definitive indicators of compromise, leaving a degree of uncertainty around the full scope of the operation.
Defenders should proactively block resolution of mybnb.info at the network perimeter and monitor DNS queries for the associated name servers ns11.knownsrv.com and ns12.knownsrv.com. Continuous scanning of the IP 194.145.208.24 for outbound connections and HTTP activity is advised. Organizations that handle booking data should educate users about unsolicited requests for login information and enforce multi‑factor authentication to mitigate potential credential theft. Ongoing threat‑intel feeds should be queried for emerging indicators related to this domain.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260712-8CA9CB- Yakalanan sayfa başlığı
- Get Your 88% Off Airbnb Voucher
- PDF belgesi
- PDF kanıtı
Hukuki dayanak
Kanıtın tam metni
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknolojiler
2 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin