api[.]arabbooking-com-dubai-desert-safari[.]webflow[.]io
“api.arabbooking-com-dubai-desert-safari.webflow.io”
api.arabbooking-com-dubai-desert-safari.webflow.io — 内容不可用. 品牌冒充:Google. 证据摘要: VirusTotal 0/91; CF Radar malicious; PhishDestroy score 45/100. 注册商: Webflow.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of the domain api.arabbooking-com-dubai-desert-safari.webflow.io, created on 12 June 2026 and hosted on the Webflow platform, indicates that it is currently flagged as a phishing site under investigation. The domain resolves to the IP address 104.18.36.248, which belongs to the content‑delivery network used by Webflow. No SSL certificate details, HTTP response codes, or page‑title information are available in the supplied intelligence, so the exact content served by the site cannot be confirmed at this time. VirusTotal records show that the domain has been scanned by 91 anti‑malware vendors, and none of those vendors reported a detection at the time of the scan.
While the lack of detections does not constitute proof of safety, it demonstrates that the domain has not yet been identified by those engines as malicious. The domain appears on one external security blocklist and has been added to the PhishDestroy blocklist, providing independent confirmation of malicious intent. No references to other reputation services such as Google Safe Browsing, OTX, or public trust scores are present in the data set. Registrar information confirms that the domain was registered through Webflow, a service that enables rapid site deployment without traditional domain‑registration steps.
The combination of a very recent creation date, association with a known phishing blocklist, and the absence of publicly available safety signals warrants heightened caution. Defenders should consider adding the domain to internal deny lists, monitor DNS queries for the IP 104.18.36.248 for anomalous activity, and enforce URL‑filtering policies that block access to the domain. Continuous re‑evaluation is advised because the threat status is listed as “active” and “under investigation,” indicating that additional malicious activity may emerge in the future.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。