bellsouth-att-sign-in-dbfbc2[.]webflow[.]io
“404 - Page not found”
bellsouth-att-sign-in-dbfbc2.webflow.io — 콘텐츠를 사용할 수 없음. 사기 유형: Credential Phishing. 증거 요약: VirusTotal 18/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, Certego, CRDF); CF Radar malicious; PhishDestroy score 100/100. 등록기관: MarkMonitor.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
The domain bellsouth-att-sign-in-dbfbc2.webflow.io has been identified as a fake login portal specifically designed to impersonate AT&T, a major telecommunications provider. Analysis indicates this infrastructure was deployed to harvest user credentials through deceptive login interfaces, a tactic commonly associated with credential theft and account compromise campaigns. The site is currently offline, though prior activity suggests it was actively targeting users seeking legitimate AT&T account access. Infrastructure analysis reveals the domain was registered through MarkMonitor, Inc., a known registrar for both legitimate and malicious entities. It resolves to the IP address 104.18.36.248, hosted on Cloudflare’s network (AS13335), a common obfuscation technique used to conceal backend servers. The domain was created on May 8, 2013, though recent malicious activity suggests it was either compromised or repurposed for fraudulent use. Security vendors flagged the domain in 18 of 95 VirusTotal scans, and it appears on two blocklists: PhishDestroy and PhishingDB. The SSL certificate, issued by Google Trust Services (WE1), further aligns with patterns observed in phishing campaigns leveraging trusted certificate authorities to appear legitimate. Current status confirms the domain is offline, though residual risk remains due to the potential for reactivation or migration to alternative infrastructure. Organizations and users are advised to block the domain and associated IP at the network level, revoke any credentials potentially exposed through this portal, and monitor for unauthorized account activity. Security teams should correlate this indicator with existing logs to identify compromised endpoints or users who may have interacted with the site prior to takedown. Proactive measures, including multi-factor authentication and user awareness training, are recommended to mitigate similar threats.
보안 신호
네트워크 보안 인텔리전스
위협 대응 Pipeline
공개 차단 목록 상태
사용 기술 · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 분석
보관된 증거
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.