Phishing detection: xfinityrefunds.com

Xfinity (Comcast)
https://xfinityrefunds.com/login Access site
Screenshot
Screenshot of xfinityrefunds.com
Investigate
URL https://xfinityrefunds.com/login
Phishunt analysis Beta
22 low suspicionheuristic risk score · not a probability
Why?
  • +5.3 Keyword match
  • +3.9 Password field
  • +3.7 Brand in domain label
  • +3.0 OpenPhish
  • +1.5 ASN reputation
  • +1.1 No CSP header
  • +1.0 Site cluster
  • +0.7 Bulletproof DNS
  • +0.6 Login text in screenshot
  • +0.4 Long domain
  • +0.4 Credential path
  • +0.2 External scripts
  • +0.2 Suspicious TLD
17 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

Impersonates Xfinity at a domain mimicking a refunds portal, with a login path harvesting customer credentials. Hosted on Microsoft Azure. Features a same-origin login form with password input and login keywords, confirmed by OpenPhish.

OpenPhishPassword fieldCredential path
AI-generated from stored detector signals - the AI never visited the site. · 2026-08-15 · confidence 80%
Domain & Network
Whois
Network
Country United StatesUnited States
ASN AS8075
TLS Cert -
External detection OpenPhish
CleanGoogle Safe Browsing · PhishTank · TweetFeed · urlscan.io
Report this phishing
Network / ASN Microsoft Corporation

Tracked from 2026-08-15 01:03 UTC  ·  Last refreshed 2026-08-24 09:30 UTC