Xfinity logo

Xfinity phishing & impersonation

18
Impersonation sightings
13
Distinct hosts
2026-08-15
Last detected
1
Official domains

ScanMalware watches every scanned site for signs it is impersonating Xfinity — the brand name in the page title or screenshot text, the brand's logo/favicon on a non-official host, and lookalike domains. A match on a host outside Xfinity's official domains is recorded below.

Official domains
xfinity.com
Also known as
comcast

Detected impersonation sites

HostTitleDetected byVerdictDate
homeaway.appXfinity Mobile Arena Guide 2026 | Philadelphia 76ers Arena | HomeAwayPage text{"verdict": "Low Risk", "confidence": 73, "risk level": "low", "risk factors": ["Brand Impersonation (Xfinity)"], "overall score": 27, "recommendations": [], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (homeaway.app)"], "password fields": 0, "impersonated brand": "Xfinity", "brand mismatch detected": true, "impersonated brand slug": "xfinity", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 19, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (homeaway.app)"], "positive": ["HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-08-15View scan →
effervescent-salamander-51d833.netlify.appSign in to XfinityPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Mixed Content", "Brand Impersonation (Xfinity)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🔐 Website serves insecure content - data may be intercepted", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (effervescent-salamander-51d833.netlify.app)"], "password fields": 1, "impersonated brand": "Xfinity", "brand mismatch detected": true, "impersonated brand slug": "xfinity", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 1}, "threat summary": ["1 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 5, "total risk": 0, "valid count": 5, "invalid count": 0, "not found count": 0}, "network security": {"score": 30, "issues": ["Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected"], "mixed content": true, "secure requests": 7, "security headers": {"detected": true}, "insecure requests": 1, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 1, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected", "⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (effervescent-salamander-51d833.netlify.app)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "No visual similarity to known brand sites"], "warnings": []}}2026-08-04View scan →
brilliant-dragon-98a015.netlify.appSign in to XfinityPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Brand Impersonation (Xfinity)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (brilliant-dragon-98a015.netlify.app)"], "password fields": 0, "impersonated brand": "Xfinity", "brand mismatch detected": true, "impersonated brand slug": "xfinity", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 1}, "threat summary": ["1 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 11, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 1, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (brilliant-dragon-98a015.netlify.app)", "Google Safe Browsing detected phishing"], "positive": ["HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-08-04View scan →
brilliant-dragon-98a015.netlify.appSign in to XfinityPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Mixed Content", "Brand Impersonation (Xfinity)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🔐 Website serves insecure content - data may be intercepted", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (brilliant-dragon-98a015.netlify.app)"], "password fields": 0, "impersonated brand": "Xfinity", "brand mismatch detected": true, "impersonated brand slug": "xfinity", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 1}, "threat summary": ["1 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "network security": {"score": 30, "issues": ["Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected"], "mixed content": true, "secure requests": 11, "security headers": {"detected": true}, "insecure requests": 1, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 1, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected", "⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (brilliant-dragon-98a015.netlify.app)", "Google Safe Browsing detected phishing"], "positive": ["HTTPS encryption used", "No visual similarity to known brand sites"], "warnings": []}}2026-08-04View scan →
vacutomerexperience.teleperformance.com.egTeleperformance | LoginPage text{"verdict": "Low Risk", "confidence": 73, "risk level": "low", "risk factors": ["Brand Impersonation (Xfinity)"], "overall score": 27, "recommendations": [], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (vacutomerexperience.teleperformance.com.eg)"], "password fields": 1, "impersonated brand": "Xfinity", "brand mismatch detected": true, "impersonated brand slug": "xfinity", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 2, "total risk": 0, "valid count": 2, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 12, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 1, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (vacutomerexperience.teleperformance.com.eg)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-28View scan →
wonderful-alpaca-9820bc.netlify.appAccount Management PortalPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Xfinity)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (wonderful-alpaca-9820bc.netlify.app)"], "password fields": 1, "impersonated brand": "Xfinity", "brand mismatch detected": true, "impersonated brand slug": "xfinity", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 1}, "threat summary": ["1 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 5, "total risk": 0, "valid count": 5, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 7, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 1, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (wonderful-alpaca-9820bc.netlify.app)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}}2026-07-26View scan →
wonderful-alpaca-9820bc.netlify.appAccount Management PortalPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Mixed Content", "Suspicious URL Patterns", "Brand Impersonation (Xfinity)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🔐 Website serves insecure content - data may be intercepted", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (wonderful-alpaca-9820bc.netlify.app)"], "password fields": 1, "impersonated brand": "Xfinity", "brand mismatch detected": true, "impersonated brand slug": "xfinity", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 1}, "threat summary": ["1 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 6, "total risk": 0, "valid count": 6, "invalid count": 0, "not found count": 0}, "network security": {"score": 30, "issues": ["Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected"], "mixed content": true, "secure requests": 7, "security headers": {"detected": true}, "insecure requests": 1, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 1, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected", "⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (wonderful-alpaca-9820bc.netlify.app)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "No visual similarity to known brand sites"], "warnings": []}}2026-07-26View scan →
xfactor300.vercel.appSign in to XfinityPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Mixed Content", "Protocol Downgrade", "Brand Impersonation (Xfinity)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🔐 Website serves insecure content - data may be intercepted", "⬇️ Connection was downgraded from HTTPS to HTTP", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (xfactor300.vercel.app)"], "password fields": 1, "impersonated brand": "Xfinity", "brand mismatch detected": true, "impersonated brand slug": "xfinity", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 1}, "threat summary": ["1 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 7, "total risk": 0, "valid count": 7, "invalid count": 0, "not found count": 0}, "network security": {"score": 25, "issues": ["Mixed content detected (HTTP resources on HTTPS page)", "2 insecure HTTP requests detected"], "mixed content": true, "secure requests": 8, "security headers": {"detected": true}, "insecure requests": 2, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 25, "issues": ["HTTPS to HTTP protocol downgrade detected"], "total redirects": 3, "blob url detected": false, "protocol downgrades": 1, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 10, "rdap data": null, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Mixed content detected (HTTP resources on HTTPS page)", "2 insecure HTTP requests detected", "HTTPS to HTTP protocol downgrade detected", "⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (xfactor300.vercel.app)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "No visual similarity to known brand sites"], "warnings": []}}2026-07-26View scan →
xf0147.vercel.appSign in to XfinityPage text{"verdict": "High Risk", "confidence": 60, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Xfinity)", "Threat-intel IoC on scanned domain (phishing): xf0147.vercel.app"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (xf0147.vercel.app)"], "password fields": 1, "impersonated brand": "Xfinity", "brand mismatch detected": true, "impersonated brand slug": "xfinity", "disguised password fields": 0, "brand impersonation detected": true}, "ioc matches": {"primary": [{"indicator": "xf0147.vercel.app", "threat type": "phishing"}], "infra ip": [], "score floor": 60}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 8, "total risk": 0, "valid count": 8, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 8, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 1, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "vercel.app", "age days": 2369, "category": "ESTABLISHED", "registrar": null, "registration date": "2020-01-28T03:03:04.240000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Matched 1 threat-intel indicator(s) on site infrastructure: xf0147.vercel.app", "⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (xf0147.vercel.app)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-24View scan →
musical-sable-b0c426.netlify.appAccount Management PortalPage text{"verdict": "High Risk (Possible Xfinity Phishing on cloud hosting)", "confidence": 80, "risk level": "high", "risk factors": ["Mixed Content", "Brand Impersonation (Xfinity)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🔐 Website serves insecure content - data may be intercepted"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (musical-sable-b0c426.netlify.app)"], "password fields": 1, "impersonated brand": "Xfinity", "brand mismatch detected": true, "impersonated brand slug": "xfinity", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 6, "total risk": 0, "valid count": 6, "invalid count": 0, "not found count": 0}, "network security": {"score": 30, "issues": ["Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected"], "mixed content": true, "secure requests": 6, "security headers": {"detected": true}, "insecure requests": 1, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 1, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Xfinity brand impersonation with a credential form on a disposable cloud-hosting/storage subdomain (musical-sable-b0c426.netlify.app) — consistent with credential phishing.", "Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected", "⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (musical-sable-b0c426.netlify.app)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-24View scan →
musical-marshmallow-037037.netlify.appAccount Management PortalPage text{"verdict": "High Risk (Possible Xfinity Phishing on cloud hosting)", "confidence": 80, "risk level": "high", "risk factors": ["Mixed Content", "Suspicious URL Patterns", "Brand Impersonation (Xfinity)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🔐 Website serves insecure content - data may be intercepted"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (musical-marshmallow-037037.netlify.app)"], "password fields": 1, "impersonated brand": "Xfinity", "brand mismatch detected": true, "impersonated brand slug": "xfinity", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 6, "total risk": 0, "valid count": 6, "invalid count": 0, "not found count": 0}, "network security": {"score": 30, "issues": ["Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected"], "mixed content": true, "secure requests": 7, "security headers": {"detected": true}, "insecure requests": 1, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 1, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Xfinity brand impersonation with a credential form on a disposable cloud-hosting/storage subdomain (musical-marshmallow-037037.netlify.app) — consistent with credential phishing.", "Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected", "⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (musical-marshmallow-037037.netlify.app)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-24View scan →
scintillating-crostata-8898c8.netlify.appAccount Management PortalPage text{"verdict": "Malicious (YARA: Magecart Skimmer - stealer)", "confidence": 90, "risk level": "malicious", "risk factors": ["Mixed Content", "Suspicious URL Patterns", "Brand Impersonation (Xfinity)"], "overall score": 85, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🔐 Website serves insecure content - data may be intercepted"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (scintillating-crostata-8898c8.netlify.app)"], "password fields": 1, "impersonated brand": "Xfinity", "brand mismatch detected": true, "impersonated brand slug": "xfinity", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 6, "total risk": 0, "valid count": 6, "invalid count": 0, "not found count": 0}, "network security": {"score": 30, "issues": ["Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected"], "mixed content": true, "secure requests": 7, "security headers": {"detected": true}, "insecure requests": 1, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 1, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Xfinity brand impersonation with a credential form on a disposable cloud-hosting/storage subdomain (scintillating-crostata-8898c8.netlify.app) — consistent with credential phishing.", "Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected", "⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (scintillating-crostata-8898c8.netlify.app)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-24View scan →
tubular-panda-354272.netlify.appAccount Management PortalPage text{"verdict": "High Risk (Possible Xfinity Phishing on cloud hosting)", "confidence": 80, "risk level": "high", "risk factors": ["Mixed Content", "Suspicious URL Patterns", "Brand Impersonation (Xfinity)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🔐 Website serves insecure content - data may be intercepted"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (tubular-panda-354272.netlify.app)"], "password fields": 1, "impersonated brand": "Xfinity", "brand mismatch detected": true, "impersonated brand slug": "xfinity", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 6, "total risk": 0, "valid count": 6, "invalid count": 0, "not found count": 0}, "network security": {"score": 30, "issues": ["Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected"], "mixed content": true, "secure requests": 7, "security headers": {"detected": true}, "insecure requests": 1, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 1, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Xfinity brand impersonation with a credential form on a disposable cloud-hosting/storage subdomain (tubular-panda-354272.netlify.app) — consistent with credential phishing.", "Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected", "⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (tubular-panda-354272.netlify.app)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-24View scan →
tubular-chimera-76bbfa.netlify.appAccount Management PortalPage text{"verdict": "Malicious (YARA: Magecart Skimmer - stealer)", "confidence": 90, "risk level": "malicious", "risk factors": ["Mixed Content", "Brand Impersonation (Xfinity)"], "overall score": 85, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🔐 Website serves insecure content - data may be intercepted"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (tubular-chimera-76bbfa.netlify.app)"], "password fields": 1, "impersonated brand": "Xfinity", "brand mismatch detected": true, "impersonated brand slug": "xfinity", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 5, "total risk": 0, "valid count": 5, "invalid count": 0, "not found count": 0}, "network security": {"score": 30, "issues": ["Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected"], "mixed content": true, "secure requests": 7, "security headers": {"detected": true}, "insecure requests": 1, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 1, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Xfinity brand impersonation with a credential form on a disposable cloud-hosting/storage subdomain (tubular-chimera-76bbfa.netlify.app) — consistent with credential phishing.", "Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected", "⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (tubular-chimera-76bbfa.netlify.app)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-24View scan →
xf0147.vercel.appSign in to XfinityPage text{"verdict": "High Risk (Possible Xfinity Phishing on cloud hosting)", "confidence": 80, "risk level": "high", "risk factors": ["Mixed Content", "Suspicious URL Patterns", "Brand Impersonation (Xfinity)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🔐 Website serves insecure content - data may be intercepted"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (xf0147.vercel.app)"], "password fields": 1, "impersonated brand": "Xfinity", "brand mismatch detected": true, "impersonated brand slug": "xfinity", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 7, "total risk": 0, "valid count": 7, "invalid count": 0, "not found count": 0}, "network security": {"score": 30, "issues": ["Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected"], "mixed content": true, "secure requests": 7, "security headers": {"detected": true}, "insecure requests": 1, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 1, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "vercel.app", "age days": 2368, "category": "ESTABLISHED", "registrar": null, "registration date": "2020-01-28T03:03:04.240000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Xfinity brand impersonation with a credential form on a disposable cloud-hosting/storage subdomain (xf0147.vercel.app) — consistent with credential phishing.", "Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected", "⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (xf0147.vercel.app)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-23View scan →
xfiyhtj.vercel.appXfinity LoginPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Mixed Content", "Brand Impersonation (Xfinity)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🔐 Website serves insecure content - data may be intercepted", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (xfiyhtj.vercel.app)"], "password fields": 1, "impersonated brand": "Xfinity", "brand mismatch detected": true, "impersonated brand slug": "xfinity", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 1}, "threat summary": ["1 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 2, "total risk": 0, "valid count": 2, "invalid count": 0, "not found count": 0}, "network security": {"score": 30, "issues": ["Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected"], "mixed content": true, "secure requests": 3, "security headers": {"detected": true}, "insecure requests": 1, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 2, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 10, "rdap data": null, "has login forms": true, "is hosting subdomain": true}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected", "⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (xfiyhtj.vercel.app)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "No visual similarity to known brand sites"], "warnings": []}}2026-07-21View scan →
xfiyhtj.vercel.appXfinity LoginPage text{"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Mixed Content", "Brand Impersonation (Xfinity)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🔐 Website serves insecure content - data may be intercepted", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (xfiyhtj.vercel.app)"], "password fields": 1, "impersonated brand": "Xfinity", "brand mismatch detected": true, "impersonated brand slug": "xfinity", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 1}, "threat summary": ["1 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "network security": {"score": 30, "issues": ["Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected"], "mixed content": true, "secure requests": 2, "security headers": {"detected": true}, "insecure requests": 1, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 1, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected", "⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (xfiyhtj.vercel.app)", "Google Safe Browsing detected phishing"], "positive": ["HTTPS encryption used", "No visual similarity to known brand sites"], "warnings": []}}2026-07-21View scan →
xfactor300.vercel.appSign in to XfinityPage text{"verdict": "High Risk (Possible Xfinity Phishing on cloud hosting)", "confidence": 80, "risk level": "high", "risk factors": ["Mixed Content", "Brand Impersonation (Xfinity)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🔐 Website serves insecure content - data may be intercepted"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (xfactor300.vercel.app)"], "password fields": 1, "impersonated brand": "Xfinity", "brand mismatch detected": true, "impersonated brand slug": "xfinity", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 7, "total risk": 0, "valid count": 7, "invalid count": 0, "not found count": 0}, "network security": {"score": 30, "issues": ["Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected"], "mixed content": true, "secure requests": 8, "security headers": {"detected": true}, "insecure requests": 1, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 2, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Xfinity brand impersonation with a credential form on a disposable cloud-hosting/storage subdomain (xfactor300.vercel.app) — consistent with credential phishing.", "Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected", "⚠️ CRITICAL: Brand impersonation detected - Xfinity branding on non-official domain (xfactor300.vercel.app)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}}2026-07-07View scan →