home-8mhvx[.]wstd[.]io
“Home”
home-8mhvx.wstd.io — لم يتم التحقق منها. انتحال العلامة التجارية: AT&T; نوع الاحتيال: Generic Phishing. ملخص الأدلة: VirusTotal 19/95 (Criminal IP, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. مسجّل النطاق: NameCheap.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of home-8mhvx.wstd.io indicates a confirmed brand impersonation campaign targeting AT&T, currently offline but previously flagged by multiple security mechanisms. The domain was registered on February 25, 2022, through NameCheap, Inc., and utilizes Cloudflare nameservers (cosmin.ns.cloudflare.com and sandra.ns.cloudflare.com), a common tactic to obscure hosting origins and evade takedowns. Infrastructure analysis reveals the domain resolved to IP 104.19.163.34, geolocated within the United States under Cloudflare’s AS13335, further suggesting the use of proxy services to mask malicious activity. The SSL certificate, issued by Let’s Encrypt, aligns with patterns observed in phishing operations leveraging short-lived, low-cost certificates to appear legitimate.
At the time of assessment, the domain returned an HTTP 401 status, indicating an unauthorized access attempt or a placeholder page, which may reflect a temporary takedown or a staging phase for future attacks. The page title 'Home' provides no additional context, and no specific phishing kit or payload has been publicly attributed to this domain. Detection data from Gridinsoft assigns a trust score of 0/100, reinforcing its classification as high-risk. The domain appears on at least one security blocklist (PhishDestroy), and 19 of 95 security vendors on VirusTotal flagged it as malicious, though the absence of recent scans or detailed reports limits granular insight into the exact threat vector.
Defenders should treat this domain as part of a broader AT&T impersonation campaign, particularly given its registration age and continued presence on blocklists despite its offline status. Organizations are advised to monitor for DNS resolution attempts, review logs for connections to 104.19.163.34, and update web filtering rules to block the domain preemptively. While the current HTTP status suggests inactivity, the infrastructure remains intact, and the domain could be reactivated with minimal effort.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب