bellsouth-att-sigining-5d1d8c[.]webflow[.]io
“Bellsouth Att Sigining”
bellsouth-att-sigining-5d1d8c.webflow.io — Контент недоступний. Тип шахрайства: Banking Phishing. Зведення доказів: VirusTotal 17/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, ESET, Emsisoft); URLQuery 3 alerts; Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 100/100. Реєстратор: Webflow.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies the domain bellsouth-att-sigining-5d1d8c.webflow.io as a high-risk phishing host currently active and posing as an AT&T sign-in page. This malicious domain leverages Webflow’s infrastructure to mimic legitimate AT&T authentication flows, deceiving users into surrendering sensitive login credentials. The campaign is categorized as a generic phishing operation with a high confidence rating due to its active status and deceptive branding.
This domain was flagged by 12 of 95 VirusTotal vendors and is explicitly blocked by Google Safe Browsing under the SOCIAL_ENGINEERING category. It resolves to IP address 104.18.36.248 and operates under an SSL certificate issued by Google Trust Services, enhancing its appearance of legitimacy. The domain is hosted on Webflow’s platform, which has been abused in multiple credential harvesting campaigns. While exact creation date and registrar details are not publicly disclosed in available intelligence, the combination of high detection rates, active hosting, and brand impersonation elevates the threat level significantly.
Security teams are urged to block access to bellsouth-att-sigining-5d1d8c.webflow.io at the network perimeter and DNS level using the domain name and resolved IP (104.18.36.248). Users should be alerted through security awareness training to avoid any AT&T-themed login prompts originating from non-official domains, especially those hosted on webflow.io or similar dynamic hosting services. Immediate investigation is recommended for any internal endpoints that may have accessed this domain, including credential rotation and log review for signs of compromise. This domain represents a credible threat to organizational security due to its active status and effective impersonation tactics.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | bellsouth-att-sigining-5d1d8c.webflow.io |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | bellsouth-att-sigining-5d1d8c.webflow.io |
malicious | Sinkholed |
| DNS4EU | bellsouth-att-sigining-5d1d8c.webflow.io |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
Visual website builder with hosted publishing.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of bellsouth-att-sigining-5d1d8c.webflow.io · checked Mar 30, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога