sbc-d25516[.]webflow[.]io
“sbc”
sbc-d25516.webflow.io — المحتوى غير متوفر. انتحال العلامة التجارية: AT&T; نوع الاحتيال: Generic Phishing. ملخص الأدلة: VirusTotal 17/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); CF Radar malicious; PhishDestroy score 95/100. مسجّل النطاق: NameCheap.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain is flagged as an elevated-risk brand impersonation threat designed to deceive users of AT&T, a major telecommunications provider. Analysis indicates the infrastructure is engineered to replicate legitimate AT&T login portals, likely for credential theft or account takeover purposes. The specific focus on AT&T branding aligns with historical patterns of targeted phishing campaigns against telecom subscribers, where attackers exploit trust in established brands to harvest sensitive information such as usernames, passwords, and multi-factor authentication codes. Infrastructure analysis reveals the following technical indicators: the domain sbc-d25516.webflow.io was registered through NameCheap, Inc., and currently resolves to the IP address 172.64.151.8, hosted on Cloudflare, Inc. (AS13335) in the United States. The domain was created on February 21, 2026, though this date may reflect registration abuse or misconfiguration. It appears on one security blocklist and is flagged by 17 out of 95 security vendors on VirusTotal, indicating moderate to high confidence in its malicious classification. The SSL certificate is issued by Google Trust Services (WE1), which, while not inherently suspicious, is commonly leveraged by threat actors to lend a false sense of legitimacy to phishing pages. The page title 'sbc' further suggests an attempt to mimic AT&T's legacy SBC Communications branding, a tactic observed in previous campaigns. Mitigation against this brand impersonation threat requires multi-layered defenses. Users should verify the authenticity of any AT&T-branded portal by cross-referencing the domain with official AT&T communications or directly navigating to att.com via a trusted browser. Organizations should implement domain-based email filtering to block messages originating from or linking to sbc-d25516.webflow.io and its associated IP (172.64.151.8). Security teams are advised to monitor for credential reuse or unusual authentication attempts from accounts that may have interacted with this domain. Given the domain's current offline status, continuous monitoring for re-emergence or similar infrastructure is recommended, as threat actors frequently rotate domains to evade detection.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب