# PhishDestroy threat dossier — team.effem.com ================================================================ Fetched: 2026-07-29 02:58:17 UTC Canonical: https://phishdestroy.io/domain/team.effem.com/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 45/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 150.171.41.10 (US, Ashburn) ASN: AS8068 Microsoft Corporation Hosting org: Microsoft Corporation Registrar: Nom-iq Ltd. dba COM LAUDE Nameservers: ["ns-1187.awsdns-20.org", "ns-1824.awsdns-36.co.uk", "ns-258.awsdns-32.com", "ns-932.awsdns-52.net"] Page title: Sign in to your account HTTP response: 302 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: DigiCert Inc / DigiCert Global G2 TLS RSA SHA256 2020 CA1 Expires: 2027-02-18 Status: INVALID chain Fingerprint: 54dbc0abff11622b7dd16b67416c219fed7c9c17eee830b7227e3b2be8e53ef7 Subject Alternative Names (related infrastructure — often same operator): - home.effem.com - mydrive.effem.com - signout.effem.com - spoadmin.effem.com - upgradetest.effem.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-28 16:13:08 UTC (by PhishDestroy tracker) Last verified: 2026-07-29 04:20:26 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 16:14:49 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is team.effem.com a Phishing Site? Analysis of team.effem.com as of July 28 2026 indicates that the domain is actively being used in a generic phishing campaign. Registration data shows the domain was registered through Nom‑iq Ltd. dba COM LAUDE. The domain resolves to four Amazon Route 53 nameservers: ns-1187.awsdns-20.org, ns-1824.awsdns-36.co.uk, ns-258.awsdns-32.com, and an incomplete fourth entry. HTTP requests receive a 302 redirect, which is a common technique for steering victims to malicious payloads. The site has been added to a single security blocklist and is listed by PhishDestroy as blocked, confirming that at least one reputable anti‑phishing service has taken action against it. VirusTotal reports that the domain was scanned by 91 vendors, none of which raised a detection; this absence of alerts does not constitute evidence of safety, as many phishing sites evade static analysis. No public information on SSL/TLS certificates, hosting IP, or geolocation is available, and the page title and content have not been harvested, leaving the exact look‑and‑feel of the landing page unknown. The current operational status is marked as active and the risk level remains under investigation. Defenders should treat the domain as malicious until further analysis proves otherwise. Recommended actions include adding team.effem.com to URL filtering and DNS blocklists, monitoring outbound connections for any attempts to resolve the domain, and employing email gateway rules that flag messages containing the host. Continuous re‑scanning on VirusTotal and similar sandboxes is advised to capture any changes in payload behavior. Incident response teams should also correlate any internal logs that reference the domain with known phishing indicators to assess potential compromise. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 54dbc0abff11622b7dd16b67416c219fed7c9c17eee830b7227e3b2be8e53ef7 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/team.effem.com/ JSON API: https://api.destroy.tools/v1/check?domain=team.effem.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 191,502 domains (82,853 alive under monitoring, 107,568 confirmed takedowns/dead). Site: https://phishdestroy.io