xfinityservices.vercel.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of xfinityservices.vercel.app
This domain appears to host a page presented as an "Account Management Portal" for Xfinity users. The screenshot shows Xfinity branding, a sign-in form requesting an email, mobile number, or username, and promotional text related to mobile billing. Based on the visible content, the page appears designed to imitate a customer login or account-access experience for a telecommunications service.
The site is hosted on a vercel.app subdomain rather than on Xfinity's primary corporate web domain. That setup may indicate a third-party hosted landing page rather than an official customer portal. No clear evidence in the scan data identifies the legitimate operator of this specific subdomain, so its ownership and authorization to use the displayed branding could not be verified from the available information.
Safety Assessment for xfinityservices.vercel.app
Multiple security signals raise concern about this page at the time of the scan. The domain was flagged by 17 out of 91 security engines, with the detections broadly classifying it as phishing or otherwise malicious. In addition, the page visually presents itself as an Xfinity sign-in portal while using a vercel.app subdomain, which may indicate an attempt to resemble a legitimate brand login page rather than an official service endpoint.
The malware scan did not identify flagged files, and major content-focused threat databases in the provided data were clean at the time of the scan. However, the domain's IP address was listed on one mail-reputation blocklist, which is a weaker signal on its own but still worth noting. In this case, that minor reputation issue is outweighed by the stronger multi-engine phishing consensus and the branding mismatch visible on the page.
Taken together, the combination of broad phishing detections, credential-harvesting style page design, and apparent brand imitation suggests elevated risk. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid TLS certificate issued by a mainstream certificate authority, with expiry shown as 2026-11-27. It is hosted on Vercel infrastructure and resolves through Vercel nameservers. DNSSEC appears to be unsigned, which is common but means DNS responses do not benefit from that additional integrity layer.
From a hosting perspective, the use of a cloud-hosted subdomain can make rapid deployment easy for both legitimate developers and abusive campaigns. No malicious files were flagged in the limited file scan, but the main technical concern here is not malware delivery; it is the apparent use of a hosted login page that may be collecting credentials while resembling a well-known telecom brand.
Share your experience with this website. Was it safe? Did you encounter any issues?