Phishing detection: xfinity101.duckdns.org

Xfinity (Comcast)
http://xfinity101.duckdns.org/verify/payment Access site
Screenshot
Screenshot of xfinity101.duckdns.org
Investigate
Domain xfinity101.duckdns.org0 CT hosts on apex
URL http://xfinity101.duckdns.org/verify/payment
Phishunt analysis Beta
45 high suspicion likely_phishingheuristic risk score · not a probability
Why?
  • +6.1 Google Safe Browsing
  • +5.3 Keyword match
  • +4.5 Brand in title
  • +4.1 Brand in screenshot
  • +3.7 Brand in domain label
  • +3.2 Brand favicon
  • +3.0 OpenPhish
  • +3.0 TweetFeed
  • +2.0 Young domain
  • +1.1 ASN reputation
  • +1.1 No CSP header
  • +1.1 No HSTS header
  • +0.7 Bulletproof DNS
  • +0.6 Suspicious TLD
  • +0.5 Long domain
  • +0.4 Credential path
  • +0.1 Deep subdomain
  • Boosted to 45: Google-flagged credential form
19 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

Site impersonates Xfinity, the US cable and internet provider, via a DuckDNS subdomain containing the brand name. It presents a payment verification page with active form inputs and is flagged as social engineering by Google Safe Browsing and OpenPhish, targeting visitors' payment credentials.

Payment fieldGoogle Safe BrowsingOpenPhish
AI-generated from stored detector signals - the AI never visited the site. · 2026-08-23 · confidence 91%
Domain & Network
Whois
Registrar Gandi SAS
Network
Country United StatesUnited States
Hosting Unified Layer
ASN AS46606
TLS Cert -
GSB category: SOCIAL_ENGINEERING
CleanPhishTank · urlscan.io
Report this phishing

Tracked from 2026-08-23 01:03 UTC  ·  Last refreshed 2026-08-25 03:30 UTC