bellsouth-att-sign-in-81225f[.]webflow[.]io
“bellsouth att sign in”
bellsouth-att-sign-in-81225f.webflow.io — المحتوى غير متوفر. نوع الاحتيال: Credential Phishing. ملخص الأدلة: VirusTotal 18/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, DNS8); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 95/100. مسجّل النطاق: NameCheap.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain, bellsouth-att-sign-in-81225f.webflow.io, is a confirmed credential theft operation impersonating AT&T's Bellsouth login portal. Analysis indicates the site was designed to harvest user credentials by mimicking the authentic AT&T sign-in interface, specifically targeting customers of the telecommunications provider. The page title, 'bellsouth att sign in,' directly aligns with AT&T's branding, increasing the likelihood of successful deception among unsuspecting users. No evidence of a crypto drainer kit or secondary payloads was observed, focusing the threat solely on credential acquisition. Technical indicators confirm the domain's malicious nature. The site is flagged by 18 out of 95 security vendors on VirusTotal, with Google Safe Browsing explicitly marking it as phishing. Infrastructure analysis reveals the domain was registered through NameCheap, Inc. on February 21, 2026, an anomalous future date suggesting potential obfuscation or system error. It resolves to IP address 104.18.36.248, hosted on Cloudflare's network (AS13335), a common tactic to obscure origin and evade takedowns. The domain appears on one security blocklist and uses an SSL certificate issued by Google Trust Services (WE1), which may lend a false sense of legitimacy to victims. The creation date discrepancy and Cloudflare hosting further indicate attempts to prolong the campaign's operational lifespan. The domain is currently offline, likely following detection and takedown efforts by security providers. However, residual risk persists due to the potential reuse of infrastructure or registration of similar domains. Organizations and users are advised to block the domain and IP address at the network level, monitor for credential reuse attempts, and implement multi-factor authentication (MFA) to mitigate account compromise risks. Given the AT&T branding, affected users should be alerted to reset passwords and review account activity for unauthorized access. The anomalous registration date warrants further investigation into potential registrar abuse or automated domain generation tactics.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب