Phishing detection: xfinityupdates.vercel.app
Xfinity (Comcast) Investigate
Domain
xfinityupdates.vercel.app0 CT hosts on apex
IP
216.198.79.131
URL
https://xfinityupdates.vercel.app
Cert
WR1
Phishunt analysis Beta
75
high suspicion likely_phishingheuristic risk score · not a probability
Why?
- +5.3 Keyword match
- +5.1 Site cluster
- +4.5 Brand in title
- +4.1 Brand in screenshot
- +3.9 Password field
- +3.7 Brand in domain label
- +3.4 Cert reuse
- +3.4 Shared IP cluster
- +3.0 OpenPhish
- +2.0 Young domain
- +1.1 ASN reputation
- +1.1 No CSP header
- +0.6 Login text in screenshot
- +0.6 Script exfil endpoint
- +0.6 Suspicious TLD
- +0.5 Long domain
- +0.3 Free CA
- +0.1 External scripts
- +0.1 Deep subdomain
- Boosted to 75: Credential exfil kit
23 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting
Site impersonates Xfinity and includes an active password input field, indicating direct credential harvesting. Hosted on Vercel PaaS with the Xfinity brand in the subdomain. Confirmed malicious by OpenPhish and clustered with other phishing infrastructure on the same IP.
Password fieldOpenPhishBrand in domain label
AI-generated from stored detector signals - the AI never visited the site. · 2026-08-22 · confidence 92%
Domain & Network
Whois
Registrar
Tucows Domains Inc
Network
Country
United States
Hosting
Amazon.com, Inc.
ASN
AS16509
TLS Cert
WR1
External detection
OpenPhish
CleanGoogle Safe Browsing · PhishTank · TweetFeed · urlscan.io
Requests
Resources
Observables
Related websites
Report this phishing
Submit to blocklists
urlscan
VirusTotal
Whois
ipinfo
Greynoise