bellsouth-att-sign-in-fa4f00[.]webflow[.]io
“404 - Page not found”
bellsouth-att-sign-in-fa4f00.webflow.io — المحتوى غير متوفر. نوع الاحتيال: Credential Phishing. ملخص الأدلة: VirusTotal 16/93 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Forcepoint ThreatSeeker); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 100/100. مسجّل النطاق: NameCheap.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain bellsouth-att-sign-in-fa4f00.webflow.io has been identified as a credential theft phishing site specifically designed to impersonate AT&T's login portal. Currently offline, this domain was part of a broader campaign targeting users of AT&T's email and internet services, leveraging the familiar BellSouth and AT&T brand names to deceive victims into surrendering their login credentials. The site's registration through NameCheap, Inc. and its creation date of February 21, 2026, suggest a recent and deliberate setup for malicious purposes.
Technical analysis reveals that this domain was flagged by 16 out of 95 security vendors on VirusTotal, indicating a high level of consensus among security tools regarding its malicious nature. Google Safe Browsing specifically flags it as phishing, and it appears on one security blocklist. The domain resolves to IP address 2606:4700:440c::ac40:9708, which is associated with Cloudflare, a common hosting provider for phishing sites due to its CDN and security features. The SSL certificate is issued by Google Trust Services, further masking the site's true intent. Despite being taken offline, the domain's rapid setup and sophisticated impersonation tactics underscore the persistent threat of credential theft campaigns.
As the domain is now offline, immediate action is not required, but users who may have interacted with this site should change their AT&T passwords and enable two-factor authentication to secure their accounts. PhishDestroy recommends monitoring for any suspicious activity and reporting similar domains to security teams or hosting providers. The high risk level and brand impersonation nature of this threat highlight the importance of verifying URLs before entering sensitive information, especially those mimicking well-known brands like AT&T.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of bellsouth-att-sign-in-fa4f00.webflow.io · checked Mar 2, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب