bookingslikethis.com - suspicious URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned bookingslikethis.com and returned a suspicious verdict (score 22), categorised as credential-harvest, impersonating binance. The page resolved to 172.67.223.155 on Cloudflare, Inc. in US. The domain was registered 3593 days ago through Synergy Wholesale Accreditations Pty Ltd. 2 domains and 2 IPs were contacted, over 11 HTTP requests. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 22) · Confidence 34%
- Scanned URL:
https://bookingslikethis.com/login - Domain: bookingslikethis.com · IP: 172.67.223.155 · AS13335 · US
- Server: cloudflare
- Page title: Bookings Like This
- HTTP status: 200 · text/html; charset=UTF-8
- Registrar: Synergy Wholesale Accreditations Pty Ltd · domain age 3593 days · created 2016-10-18
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Nov 17 22: · subject CN=bookingslikethis.com
- HTTP requests captured: 11 · cookies set: 2 · outgoing links: 1
- Scan tier: standard · observed 2026-08-20 20:18:14 UTC
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Valid TLS, no impersonation or off-origin credential post
- Certificate issued < 48h ago
- Matches phishing-kit family "Binance / Crypto Exchange Kit"
Detected technologies
- Cloudflare
- Cloudflare Insights
Contacted infrastructure
- 172.67.223.155 - AS13335 Cloudflare, Inc. (United States)
- 104.16.80.73 - AS13335 Cloudflare, Inc. (United States)
Observed indicators
- bookingslikethis.com
- static.cloudflareinsights.com
- 172.67.223.155
- 104.16.80.73
- https://bookingslikethis.com/login
- https://bookingslikethis.com/manifest.json
- https://bookingslikethis.com/favicon/apple-touch-icon.png
- https://bookingslikethis.com/favicon/favicon-32x32.png
- https://bookingslikethis.com/favicon/favicon-16x16.png
- https://bookingslikethis.com/favicon/manifest.json
- https://bookingslikethis.com/favicon/safari-pinned-tab.svg
- https://bookingslikethis.com/assets/js/ie/html5shiv.js
- https://bookingslikethis.com/assets/css/main.css
- https://bookingslikethis.com/assets/css/sltems.css
- https://bookingslikethis.com/assets/css/ie9.css
- https://bookingslikethis.com/assets/css/ie8.css
- https://bookingslikethis.com/images/blt-logo.png
- https://bookingslikethis.com/password/reset
- https://static.cloudflareinsights.com/beacon.min.js/v4513226cdae34746b4dedf0b4dfa099e1781791509496
Questions about bookingslikethis.com
- Is bookingslikethis.com safe?
- No. MalwareAnalyzer scanned bookingslikethis.com on 20 Aug 2026 and returned a suspicious verdict with a score of 22 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- Does bookingslikethis.com belong to binance?
- No. This page claims the identity of binance but nothing establishes that binance operates it, which is what impersonation means here. Compare the certificate organisation and the registrant against the brand's real properties.
- How was bookingslikethis.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of bookingslikethis.com · Other binance phishing domains
Scanned on MalwareAnalyzer by Cyble · Open interactive scan