# PhishDestroy threat dossier — connectt-xfinitys-auth.weebly.com ================================================================ Fetched: 2026-04-28 02:25:07 UTC Canonical: https://phishdestroy.io/domain/connectt-xfinitys-auth.weebly.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Credential Phishing Targeted brand: Google ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 21/94 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, Ermes, ESET, Emsisoft, Forcepoint ThreatSeeker, Fortinet, G-Data, Google Safebrowsing, Gridinsoft, Kaspersky, LevelBlue, Lionic, MalwareURL, Netcraft, Sophos, VIPRE, Webroot Google Safe Browsing: FLAGGED ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 74.115.51.9 (US, Oakland) ASN: AS27647 Weebly, Inc. Hosting org: Weebly, Inc. Registrar: MarkMonitor, Inc. Nameservers: ns-123.awsdns-15.com, ns-1500.awsdns-59.org, ns-1797.awsdns-32.co.uk, ns-646.awsdns-16.net Registered: 2026-04-23 Page title: Sign in to xfinity HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E8 Expires: 2026-07-11 Status: INVALID chain Fingerprint: 5030d04ba7102135fff71e4de7c4b13a750ef5e1e8efa91f7ba49893b21d9e74 Subject Alternative Names (related infrastructure — often same operator): - weebly.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-23 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-23 16:16:51 UTC (by PhishDestroy tracker) Last verified: 2026-04-27 23:12:51 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dba79-c0d0-73cd-a03b-906cb0179539/ Wayback Machine: https://web.archive.org/web/*/connectt-xfinitys-auth.weebly.com crt.sh CT logs: https://crt.sh/?q=%25.connectt-xfinitys-auth.weebly.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=connectt-xfinitys-auth.weebly.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/connectt-xfinitys-auth.weebly.com URLhaus: https://urlhaus.abuse.ch/host/connectt-xfinitys-auth.weebly.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-23 16:18:55 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies connectt-xfinitys-auth.weebly.com as an active credential theft portal masquerading as an Xfinity authentication interface. The domain employs a Weebly-hosted phishing page designed to harvest Comcast/Xfinity account credentials under the guise of a security update or identity verification. No advanced drainer kit components were detected in the available telemetry, suggesting a basic but effective social engineering approach leveraging brand impersonation. The lure likely targets Xfinity customers through phishing emails, SMS, or browser notifications, exploiting urgency to bypass user scrutiny. Given the domain's Weebly hosting and minimal obfuscation, this appears to be a lower-tier operation optimized for volume over sophistication. This domain presents multiple concrete technical indicators confirming its malicious nature. VirusTotal reports a detection ratio of 14/95 security vendors as of the latest scan, with Google Safe Browsing explicitly flagging it under SOCIAL_ENGINEERING. The domain was registered through MarkMonitor, Inc., a common registrar leveraged by threat actors for domain anonymization, and resolves to IP address 74.115.51.9. Domain creation occurred on March 29, 2006, indicating long-term ownership possibly compromised or repurposed for malicious use. Despite its age, the domain has been weaponized recently, as evidenced by active phishing campaigns. As of the latest scan, connectt-xfinitys-auth.weebly.com remains active and accessible. PhishDestroy strongly advises immediate blacklisting of this domain and IP address 74.115.51.9 at the network and endpoint levels. Users should be notified to avoid interacting with any links or attachments referencing this domain, especially those claiming to be from Xfinity or Comcast. While the domain currently poses a high risk due to its active status and brand impersonation, its reliance on a public hosting platform like Weebly may increase the likelihood of takedown by hosting providers upon notification. However, persistent monitoring is recommended due to the potential for rapid domain rotation or infrastructure changes. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 4d27526198ac873ccec96935198e0fb9 TLS cert SHA-256: 5030d04ba7102135fff71e4de7c4b13a750ef5e1e8efa91f7ba49893b21d9e74 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/connectt-xfinitys-auth.weebly.com/ JSON API: https://api.destroy.tools/v1/check?domain=connectt-xfinitys-auth.weebly.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io