attonlinesit001[.]webflow[.]io
“attonlinesit001”
已存储的观测记录
观测到的标题差异
证据摘要
The domain attonlinesit001.webflow.io was registered on May 08, 2013 and is listed as being managed by MarkMonitor, Inc., a registrar commonly used by legitimate enterprises. The site presents a page title identical to the domain name, "attonlinesit001," and serves an SSL certificate issued by Google Trust Services under the WE1 designation, indicating the use of a valid TLS chain. DNS resolution points to the Cloudflare edge address 172.64.151.8, which is associated with AS13335 Cloudflare, Inc., and the infrastructure reports support for HTTP/3. Nameserver records show journey.ns.cloudflare.com and lamar.ns.cloudflare.com, confirming the Cloudflare front‑end.
Security telemetry shows the domain is currently offline, returning an HTTP 404 status, and has been taken down by the PhishDestroy takedown service. Despite the offline state, the domain appears on one public security blocklist and has been flagged by 15 of 95 VirusTotal scanners, reinforcing a malicious classification. The Scamadviser trust score of 1 / 100 further reflects a high likelihood of abuse. The domain explicitly impersonates the AT&T brand, aligning with a brand‑impersonation threat profile.
Uncertainty remains regarding the exact payload or credential‑collection mechanisms that may have been hosted before takedown, as no page content beyond the title has been captured. Defenders should ensure that outbound traffic to the IP 172.64.151.8 is blocked at the perimeter, update URL filtering policies to include this fully qualified domain name, and monitor for any sub‑domains or similar Cloudflare‑hosted assets that reference AT&T. Continued observation of related blocklist entries and periodic re‑scans of the domain are recommended to detect any re‑activation attempts. Incident response teams should advise users to verify any unsolicited communications claiming to originate from AT&T and to report suspicious URLs to the organization’s security portal.
Data Coverage
安全信号
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
检测时间线
-
域名状态
可访问 → 无法访问
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
技术
识别出 2 项高置信度技术
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of attonlinesit001.webflow.io · checked Mar 2, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控