bellsouth-att-sign-in-9e4506[.]webflow[.]io
“bellsouth att sign In”
bellsouth-att-sign-in-9e4506.webflow.io — Inhalt nicht verfügbar. Markenidentität: AT&T; Betrugstyp: Generic Phishing. Zusammenfassung der Beweislage: VirusTotal 14/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); CF Radar malicious; PhishDestroy score 97/100. Registrar: MarkMonitor.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Analysis of bellsouth-att-sign-in-9e4506.webflow.io indicates this domain is a confirmed brand impersonation targeting AT&T customers, currently offline as of July 23, 2026. The domain was created on May 8, 2013, though the specific phishing content appears to have been hosted recently under the Webflow.io subdomain infrastructure. Infrastructure analysis reveals the domain resolves to 172.64.151.8, an IP address assigned to Cloudflare, Inc. (AS13335) in the United States. The domain is proxied through Cloudflare nameservers (journey.ns.cloudflare.com, lamar.ns.cloudflare.com) and uses Cloudflare technologies including HTTP/3, which is consistent with threat actors leveraging CDN services to obscure hosting origins and evade takedowns. The page title captured from the site was 'bellsouth att sign In,' directly referencing AT&T's legacy BellSouth brand, a common tactic in credential harvesting campaigns targeting telecom customers.
The domain is flagged by 14 of 95 security vendors on VirusTotal, and appears on at least one security blocklist, including PhishDestroy. Scamadviser assigned a trust score of 1/100, further supporting its classification as malicious. The domain's SSL certificate is issued by Google Trust Services (WE1), which is not inherently suspicious but is frequently used by phishing sites due to its accessibility and legitimacy perception. At the time of analysis, the domain returns an HTTP 404 status, indicating the phishing page has been removed or the site is no longer active.
However, the domain itself remains registered through MarkMonitor, Inc., a registrar commonly used for both legitimate and malicious domains. Defenders should treat this domain as a confirmed phishing threat, particularly for AT&T/BellSouth customers, and consider blocking it at the DNS or proxy level. While the site is offline, monitoring for reactivation or domain reuse is recommended, as threat actors often repurpose infrastructure for new campaigns.
Sicherheitssignale
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % KonfidenzHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % KonfidenzVirusTotal-Analyse
Archivierte Beweise
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt