booking-dubaii-shopping.webflow.io
“Dubai Shopping Guide 2024 – Top Malls and Markets with Booking.com”
booking-dubaii-shopping.webflow.io — 可达 · 访问受限 (HTTP 403). 品牌冒充:Unknown; 诈骗类型:Impersonation. 证据摘要: VirusTotal 6/91 (alphaMountain.ai, Emsisoft, Forcepoint ThreatSeeker, Fortinet, Netcraft); CF Radar malicious; PhishDestroy score 70/100. 注册商: Webflow.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
证据摘要
The domain booking-dubaii-shopping.webflow.io is currently flagged as a phishing resource. Infrastructure analysis shows the domain resolves to the IP address 104.18.36.248, which is associated with the Webflow hosting platform. Registration data indicates the domain was created through Webflow, a legitimate website‑building service, suggesting the attacker leveraged a trusted registrar to obtain a seemingly benign SSL certificate and hosting environment.
Threat intelligence from multiple sources places the domain on one external blocklist and confirms that PhishDestroy has actively blocked it. VirusTotal scans report that six out of ninety‑one security vendors have identified the domain as malicious, reinforcing the suspicion of phishing activity despite the relatively low detection count. No public Safe Browsing, Open Threat Exchange (OTX), SSL certificate details, HTTP status codes, trust‑score metrics, or page‑title information are presently available, leaving those vectors unverified at this time.
The limited visibility into the site’s content means that analysts cannot yet confirm the exact phishing lure or target brand. Defenders should treat the domain as high‑risk: add the domain and its resolved IP address to outbound filtering rules, monitor DNS queries for repeated resolutions, and ensure that any internal phishing‑detection systems ingest the blocklist and VirusTotal indicators. Continuous re‑evaluation is advised, as additional telemetry such as page content snapshots or further vendor detections could clarify the attack’s scope and enable more precise mitigation steps.
网络安全情报
Forensic History & Detection Timeline
-
Domain Status Transition Jul 29, 2026 · 12:07 UTCDomain state transitioned from alive to dead.
-
Threat First Observed Jul 29, 2026 · 06:48 UTCDomain ingestion complete. Initial state is marked as unknown pointing to IP
104.18.36.248.
威胁响应 Pipeline
公共封禁名单状态
Evasion analysis
Cloaking suspected: scanner and victim titles differ
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not yet scanned
- Last cloaking scan
- Server header seen by scanner
cloudflare
Scanner note: cloudflare_ban: raw=cf_phishing_block; http=403; via=https_proxy; server=cloudflare; provider_error=cloudflare_phishing_interstitial
Provider response during scan: cloudflare_phishing_interstitial
技术 · 2 identified
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of booking-dubaii-shopping.webflow.io · checked Jul 29, 2026
社区报告
由 1 名社区成员报告;首次发现于 2026年6月12日
- 已存储报告
- 1
- 已报告的唯一 URL
- 1
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。