MALICIOUS — CRITICAL
teamslivechat[.]us
This domain, teamslivechat.us, is flagged as an active phishing site targeting Microsoft Teams credentials.
- VirusTotal
- 16/94
- Blocklists
- 2 · MetaMask, SEAL
- التوفر
- آخر نشاط معروف · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
teamslivechat.us — آخر نشاط معروف (HTTP 200). ملخص الأدلة: VirusTotal 16/94; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 100/100.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
This domain, teamslivechat.us, is flagged as an active phishing site targeting Microsoft Teams credentials. Registered on April 20, 2026, the domain resolves to 198.54.119.191, an IP address associated with a known hosting provider in the United States. Infrastructure analysis reveals the domain is hosted on a server with a Sectigo-issued SSL certificate, which, while providing encryption, does not validate the legitimacy of the site. The domain appears on three security blocklists and is blocked by multiple threat intelligence platforms, including PhishDestroy, MetaMask, and SEAL, indicating confirmed malicious activity. The domain’s MX records point to mx1-hosting.jellyfish.systems, suggesting potential email capabilities that could be leveraged for further phishing campaigns or credential harvesting. With a trust score of 0/100 and detection by 16 out of 95 security vendors on VirusTotal, the domain exhibits strong indicators of malicious intent. AlienVault OTX further corroborates this assessment, listing the domain in 22 threat intelligence pulses, which often include reports of credential theft or impersonation of collaboration platforms. While the exact content of the site has not been analyzed, the domain name and associated intelligence strongly suggest it is designed to mimic Microsoft Teams login pages or chat interfaces. Defenders should treat this domain as high-risk and prioritize blocking it at the network level, including DNS and web proxy filters. Security teams should also monitor for any attempts to access this domain from internal networks, as such activity may indicate compromised credentials or ongoing phishing attempts. Given the domain’s recent registration and active status, it is likely part of a broader campaign, and defenders should review logs for related indicators of compromise, such as connections to the hosting IP or associated MX records.
نطاق تغطية البيانات12 recorded checks
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تحليل VirusTotal
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.