bellsouth-att-sign-in-9e4506[.]webflow[.]io
“bellsouth att sign In”
bellsouth-att-sign-in-9e4506.webflow.io — सामग्री अनुपलब्ध. ब्रांड प्रतिरूपण: AT&T; घोटाले का प्रकार: Generic Phishing. साक्ष्य सारांश: VirusTotal 14/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); CF Radar malicious; PhishDestroy score 97/100. रजिस्ट्रार: MarkMonitor.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Analysis of bellsouth-att-sign-in-9e4506.webflow.io indicates this domain is a confirmed brand impersonation targeting AT&T customers, currently offline as of July 23, 2026. The domain was created on May 8, 2013, though the specific phishing content appears to have been hosted recently under the Webflow.io subdomain infrastructure. Infrastructure analysis reveals the domain resolves to 172.64.151.8, an IP address assigned to Cloudflare, Inc. (AS13335) in the United States. The domain is proxied through Cloudflare nameservers (journey.ns.cloudflare.com, lamar.ns.cloudflare.com) and uses Cloudflare technologies including HTTP/3, which is consistent with threat actors leveraging CDN services to obscure hosting origins and evade takedowns. The page title captured from the site was 'bellsouth att sign In,' directly referencing AT&T's legacy BellSouth brand, a common tactic in credential harvesting campaigns targeting telecom customers.
The domain is flagged by 14 of 95 security vendors on VirusTotal, and appears on at least one security blocklist, including PhishDestroy. Scamadviser assigned a trust score of 1/100, further supporting its classification as malicious. The domain's SSL certificate is issued by Google Trust Services (WE1), which is not inherently suspicious but is frequently used by phishing sites due to its accessibility and legitimacy perception. At the time of analysis, the domain returns an HTTP 404 status, indicating the phishing page has been removed or the site is no longer active.
However, the domain itself remains registered through MarkMonitor, Inc., a registrar commonly used for both legitimate and malicious domains. Defenders should treat this domain as a confirmed phishing threat, particularly for AT&T/BellSouth customers, and consider blocking it at the DNS or proxy level. While the site is offline, monitoring for reactivation or domain reuse is recommended, as threat actors often repurpose infrastructure for new campaigns.
सुरक्षा संकेत
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% विश्वासHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% विश्वासवायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।