VirusTotal
16 / 91
“checkbnb.online”
checkbnb.online — Контент недоступний. Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); Spamhaus DBL_PHISH; 1 external blocklist match (ScamSniffer); PhishDestroy score 95/100. Реєстратор: GoDaddy.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
16 / 91
DBL_PHISH
checked — no detections recorded
Повідомитиno community references
Повідомитиprovider verdict: clean
Повідомитизбережений звіт
ПовідомитиАналіз завершено
Повідомити14 перевірено — блокувань немає
Checked; no threat flag recorded
ПовідомитиThis domain, checkbnb.online, is identified as a credential theft operation impersonating the Airbnb platform. Analysis indicates the site presents fraudulent login interfaces designed to harvest user credentials, including usernames, passwords, and potentially two-factor authentication codes. The threat extends to financial risk, as compromised accounts may be used for unauthorized bookings, payment fraud, or resale on dark web marketplaces. The campaign appears targeted at users seeking short-term rental services, exploiting trust in the Airbnb brand to facilitate account takeovers. Infrastructure analysis reveals the domain was registered on October 28, 2025, through GoDaddy.com, LLC, a registrar frequently abused for malicious operations due to its accessibility and bulk registration options. The domain resolves to the IP address 77.245.76.110, which has been associated with prior phishing activity. Detection metrics confirm elevated risk: 16 of 95 security vendors on VirusTotal flagged the domain as malicious, while it appears on two independent security blocklists, including PhishDestroy and ScamSniffer. The creation date suggests the campaign is relatively recent, aligning with observed trends in brand impersonation targeting peak travel seasons. Users who visited checkbnb.online should immediately revoke any entered credentials, particularly for Airbnb or linked email accounts. Enable multi-factor authentication (MFA) on all associated services, using app-based or hardware tokens rather than SMS-based methods. Monitor financial statements for unauthorized transactions and report suspicious activity to the legitimate platform. If payment details were submitted, contact financial institutions to initiate fraud alerts. Security teams should block the domain and IP 77.245.76.110 at the network perimeter, and review logs for connections to these indicators. The domain's current offline status does not preclude future reactivation; continuous monitoring is advised.
Full extracted values, their blockchain and collection source. An address found in page content does not establish who controls it.
0x1824b4c06c90B28a2D34D7898a30ecbFcB5B87B2Format validated · Domain analysis0x55d398326f99059fF775485246999027B3197955Format validated · Domain analysis0x8bc152da45f60b40b52ffa4cc0cdd13ac236b8a3Format validated · Domain analysisIoC extraction recorded 2026-08-01 04:09:50 UTC
Збережені дані спостережень за взаємодією веб-сканера та браузера для цього хоста, а також перевірка відбитків у режимі реального часу для систем розподілу трафіку типу «Кейтаро».
Примітка щодо сканера: unavailable: raw=connection_error; http=0; via=http_proxy; error=SOCKSHTTPConnectionPool(host='checkbnb.online', port=80): Max retries exceeded with url: / (Caused by NewConnectionError
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
ns17.domaincontrol.comns18.domaincontrol.comLocation describes the IP network.
13 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
Повідомив 1 учасник спільноти; уперше помічено 30.05.2026
PD-20260530-D9921E Recipient: abuse@iomart.com Policy Violations: Acceptable Use Policy (AUP): The domain checkbnb.online is engaged in phishing activities, which directly contravenes the AUP prohibiting illegal activities, fraud, and deception. Terms of Service (TOS): The registrar reserves the right to suspend or terminate services for violations, and the use of this domain for phishing is a clear violation of these terms. Applicable Laws (Unknown): Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and networks, which is applicable to phishing schemes. Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals or entities via electronic communications, including phishing. Anti-Phishing Consumer Protection Act: This act specifically targets phishing activities, making it illegal to use deceptive means to acquire sensitive information. Regulatory Note: Failure to take action against this domain may result in liability for facilitating illegal activities, and could lead to regulatory scrutiny or enforcement actions against your organization.
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Template-based draft · optional AI wording assistance requires separate consent
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразДодавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиОстанні звіти про фішинг і помічені зміни доступності
ВідстежуватиСлідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога