bellsouth-att-sign-in-dbfbc2[.]webflow[.]io
“404 - Page not found”
bellsouth-att-sign-in-dbfbc2.webflow.io — Контент недоступен. Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 18/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, Certego, CRDF); CF Radar malicious; PhishDestroy score 100/100. Регистратор: MarkMonitor.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain bellsouth-att-sign-in-dbfbc2.webflow.io has been identified as a fake login portal specifically designed to impersonate AT&T, a major telecommunications provider. Analysis indicates this infrastructure was deployed to harvest user credentials through deceptive login interfaces, a tactic commonly associated with credential theft and account compromise campaigns. The site is currently offline, though prior activity suggests it was actively targeting users seeking legitimate AT&T account access. Infrastructure analysis reveals the domain was registered through MarkMonitor, Inc., a known registrar for both legitimate and malicious entities. It resolves to the IP address 104.18.36.248, hosted on Cloudflare’s network (AS13335), a common obfuscation technique used to conceal backend servers. The domain was created on May 8, 2013, though recent malicious activity suggests it was either compromised or repurposed for fraudulent use. Security vendors flagged the domain in 18 of 95 VirusTotal scans, and it appears on two blocklists: PhishDestroy and PhishingDB. The SSL certificate, issued by Google Trust Services (WE1), further aligns with patterns observed in phishing campaigns leveraging trusted certificate authorities to appear legitimate. Current status confirms the domain is offline, though residual risk remains due to the potential for reactivation or migration to alternative infrastructure. Organizations and users are advised to block the domain and associated IP at the network level, revoke any credentials potentially exposed through this portal, and monitor for unauthorized account activity. Security teams should correlate this indicator with existing logs to identify compromised endpoints or users who may have interacted with the site prior to takedown. Proactive measures, including multi-factor authentication and user awareness training, are recommended to mitigate similar threats.
Сигналы безопасности
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание