att[.]kexia[.]icu
साक्ष्य सारांश
This domain, att.kexia.icu, is flagged as a generic phishing site designed to impersonate AT&T’s official login portal. Analysis indicates the threat actor deployed a credential-harvesting page to capture user account details, likely targeting customers of the telecommunications provider. No specific drainer kit signatures have been identified, but the infrastructure aligns with common phishing-as-a-service (PhaaS) frameworks used for large-scale credential theft campaigns. Infrastructure analysis reveals the domain was registered on February 21, 2026, through an undisclosed registrar. It resolves to IP address 172.67.153.130, hosted on Cloudflare’s network (AS13335), a common tactic to obscure origin servers. VirusTotal detection shows 19 out of 95 security vendors flagging the domain as malicious. The domain appears on one security blocklist and was not listed in Google Safe Browsing at the time of analysis. The SSL certificate is issued by WE1, a low-assurance provider frequently used in phishing operations. As of the latest assessment, att.kexia.icu has been taken offline, likely following abuse reports or automated takedown procedures. The domain was blocked by at least one security provider, and Cloudflare’s infrastructure may have suspended the associated hosting. Despite its offline status, residual risk remains for users who may have interacted with the site prior to takedown. Organizations are advised to monitor for credential reuse attempts and implement multi-factor authentication (MFA) to mitigate account compromise. Network defenders should update blocklists to include the domain and its resolving IP to prevent future access attempts.
Data Coverage
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 13/08/2026
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
SHORTDOT ज़ोन · सार्वजनिक साक्ष्य
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
फॉरेंसिक इंटेलिजेंस
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।