bellsouth-att-sign-in-339ec8[.]webflow[.]io
“bellsouth att sign in”
bellsouth-att-sign-in-339ec8.webflow.io — Konten tidak tersedia. Peniruan identitas merek: AT&T; Jenis penipuan: Generic Phishing. Ringkasan bukti: VirusTotal 16/93 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Forcepoint ThreatSeeker); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 95/100. Registrar: MarkMonitor.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain, bellsouth-att-sign-in-339ec8.webflow.io, resolves to the Cloudflare‑hosted IP 172.64.151.8 (AS13335, United States). The site returns HTTP 403, indicating that the content is currently inaccessible, and the domain is listed as taken offline. Registration data show the domain was created on 08 May 2013 and was purchased through MarkMonitor, Inc., a registrar commonly used for legitimate brand assets. The authoritative nameservers are journey.ns.cloudflare.com and lamar.ns.cloudflare.com, confirming Cloudflare as the DNS provider.
The TLS certificate is issued by Google Trust Services under the WE1 identifier, which is a legitimate public‑trusted CA. The page title observed in prior scans is “bellsouth att sign in”, and the domain has been classified as an AT&T brand impersonation. Google Safe Browsing flags the site for social engineering, and one external blocklist (PhishDestroy) has already added the domain. VirusTotal analysis shows that 16 of 93 scanned security vendors flagged the domain, demonstrating a moderate consensus of malicious behavior.
Detected infrastructure technologies include Cloudflare and HTTP/3, both typical for fast‑forwarding services but not indicative of benign intent in this context. Given the combination of brand impersonation, social‑engineering classification, multi‑vendor detections, and the presence on a phishing blocklist, defenders should treat any future resolution of this domain as malicious. Recommendations include adding the domain to internal deny lists, monitoring DNS queries for the IP 172.64.151.8, and configuring web‑proxy rules to block HTTP requests that match the observed page title or TLS certificate fingerprint. Continuous re‑evaluation is advised in case the domain is re‑hosted or the status changes.
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Teknologi · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Keyakinan 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Keyakinan 100%Analisis VirusTotal
Bukti Terarsip
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of bellsouth-att-sign-in-339ec8.webflow.io · checked Mar 2, 2026
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive