att-resetaccount.netlify.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of att-resetaccount.netlify.app
This website appears to present itself as an AT&T account sign-in page, using AT&T branding, a login form, and account-related wording such as "Sign in to my Account." The page title and screenshot suggest it is designed to collect user credentials or otherwise imitate a telecommunications customer portal rather than provide independent content or services of its own.
The domain is hosted on a Netlify subdomain rather than an official AT&T-owned domain, while also referencing assets from signin.att.com. Based on the domain structure, page design, and classification data, the site appears to be an impersonation-style login page targeting users who may believe they are interacting with AT&T. There is no clear indication in the scan data that this page is operated by AT&T or an authorized partner.
Safety Assessment for att-resetaccount.netlify.app
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 23 out of 91 security engines, and multiple web-classification providers categorized it as phishing or fraud-related content. In addition, major threat-database checks showed social-engineering listings, and another phishing database also listed the page. Although one malware scan reported no malicious files, that result does not outweigh the broader phishing consensus because credential-harvesting pages often contain little or no malware code.
The page also appears to imitate a telecommunications login portal while being hosted on a third-party subdomain, which is a common pattern in credential theft campaigns. The use of AT&T branding, the account-reset wording in the subdomain, and the login-focused screenshot may increase the likelihood that visitors could mistake it for an official sign-in page. The domain's IP address is also listed on one mail-reputation blocklist, which is a weaker signal than phishing detections but still adds minor caution.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid TLS certificate issued by DigiCert, with expiry shown as 2027-03-19, which means the connection appears encrypted in transit. However, a valid certificate only indicates HTTPS availability and does not verify that the page is legitimate. The site is hosted on Netlify infrastructure backed by AWS EC2 in Frankfurt, Germany, and the domain uses Netlify-related nameservers. DNSSEC appears to be unsigned.
From a security perspective, the main concern is not transport security but apparent brand impersonation and phishing-related detection consensus. The page is hosted on a netlify.app subdomain rather than an official AT&T domain, while visually resembling an AT&T login page and referencing an AT&T asset URL, which may be consistent with a deceptive credential-collection setup.
Share your experience with this website. Was it safe? Did you encounter any issues?