bellsouth-att-signing-c0218f[.]webflow[.]io
“Bellsouth Att Signing”
bellsouth-att-signing-c0218f.webflow.io — Contenido no disponible. Suplantación de marca: AT&T; Tipo de estafa: Generic Phishing. Resumen de las pruebas: VirusTotal 15/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); PhishDestroy score 100/100. Registrador: MarkMonitor.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of bellsouth-att-signing-c0218f.webflow.io, observed on July 23, 2026, indicates an elevated‑risk brand‑impersonation campaign targeting AT&T. The domain resolves to 172.64.151.8, an address owned by AS13335 Cloudflare, Inc., located in the United States. DNS services are provided by Cloudflare nameservers journey.ns.cloudflare.com and lamar.ns.cloudflare.com. The site presented an HTTP 404 response and a TLS certificate issued by Google Trust Services under the WE1 root, confirming that transport encryption was in place at the time of observation. Registration information shows the domain was created on May 08 2013 and is listed under MarkMonitor, Inc., a registrar commonly associated with legitimate brand owners. Despite the legitimate‑looking registration, the page title “Bellsouth Att Signing” and the classification as a brand‑impersonation threat indicate malicious intent.
Security‑vendor scanning on VirusTotal recorded 15 positive detections out of 95 scanners, and the domain appears on a single external blocklist. Scamadviser assigned a trust score of 1 / 100, reflecting extreme lack of credibility. The domain has been taken offline and is flagged by PhishDestroy. Current evidence shows the infrastructure is typical of abuse‑as‑a‑service patterns that leverage Cloudflare’s CDN and HTTP/3 capabilities to hide origin servers. Defenders should continue to block the IP address 172.64.151.8 and the fully qualified domain name, update URL filtering rules, and monitor for any re‑registration attempts. Logging of DNS queries for the Cloudflare nameservers may aid in detecting future campaigns that reuse similar naming conventions.
Because the domain is no longer active, remediation focus should be on preventing reuse of the same hosting assets and ensuring that any user‑agent that may have previously accessed the site is cleared of potential malicious payloads.
Señales de seguridad
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % de confianzaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % de confianzaAnálisis de VirusTotal
Evidencias archivadas
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.