bellsouth-att-signing-83d69c.webflow.io
Category: Phishing And Fraud
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of bellsouth-att-signing-83d69c.webflow.io
This domain appears to host a Webflow-built page themed around BellSouth and AT&T account access. The page title, branding, and screenshot show an email sign-in form labeled for BellSouth/AT&T users, alongside explanatory text about BellSouth legacy email accounts and references to AT&T-managed login services.
Based on the domain structure, this does not appear to be an official AT&T or BellSouth-owned login domain. Instead, it appears to be a page published under a webflow.io subdomain, which is commonly used for hosted landing pages and prototypes. The content suggests an attempt to present itself as a telecommunications-related login page rather than an independent informational website.
Safety Assessment for bellsouth-att-signing-83d69c.webflow.io
Several risk indicators are present in this scan. The domain was flagged by 12 out of 90 security engines, with multiple detections describing the page as phishing-related. In addition, the screenshot shows a credential-entry form using BellSouth and AT&T branding on a third-party hosting subdomain rather than what appears to be an official telecom login domain. That combination may indicate an attempt to collect account credentials by imitating a recognizable service.
The malware file scan did not detect malicious files at the time of this scan, and major content-malware blacklist checks were otherwise largely clean. However, a clean file scan does not rule out credential theft, since phishing pages often rely on simple HTML forms rather than malware payloads. The domain's IP address is also listed on one mail-reputation blocklist, which is a weaker signal than phishing detections but still adds some caution.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is served over HTTPS with a valid TLS certificate issued by a mainstream certificate authority, and it appears to be proxied through Cloudflare infrastructure with hosting geolocated to Canada. The page also loads assets from Webflow and Cloudflare-related services, which is consistent with a hosted landing page rather than a standalone enterprise deployment.
DNSSEC appears to be unsigned, and the site uses Cloudflare nameservers. No malicious files were flagged in the limited file scan, but the main concern here appears to be page purpose and branding misuse rather than exploit delivery. The use of a third-party hosted subdomain for a telecom-branded login page is a notable technical and trust concern.
Share your experience with this website. Was it safe? Did you encounter any issues?