VirusTotal
3 / 94
3 / 94
checked — no detections recorded
Reportchecked — no match recorded
no community references
Reportstored report
Report Analysis completed
Report12 checked — no blocks
Report stored; verdict not recorded
ReportChecked; no threat flag recorded
Reportteams-connect-voice.online — Microsoft Teams Voice Phishing Campaign — Status Active
PhishDestroy identifies teams-connect-voice.online as an active Microsoft Teams voice phishing campaign. The domain is currently under investigation with a risk level classified as under_investigation. The threat involves impersonation of Microsoft Teams voice services, likely targeting users with fraudulent login prompts or fake voice call notifications.
This domain was flagged by 3 of 95 VirusTotal vendors as of the latest scan. The domain resolves to IP 188.114.96.3 and is registered through HOSTINGER operations, UAB. Domain creation date is April 06, 2026, indicating a recently established infrastructure. The domain utilizes a valid SSL certificate from Let's Encrypt, enhancing its deceptive appearance. Current blocklist count and trust scores remain unverified due to limited detection coverage.
The campaign remains active and poses a credible risk due to its Microsoft Teams impersonation and valid SSL certificate. Organizations and users are advised to block the domain teams-connect-voice.online at the network perimeter and inspect DNS logs for resolution attempts to IP 188.114.96.3. Exercise heightened scrutiny for unsolicited voice or login prompts referencing Microsoft Teams. Users should navigate directly to official Microsoft domains and enable multi-factor authentication to mitigate credential theft. Monitor endpoints for anomalous network connections to the identified IP. Report any observed activity to internal security teams and threat intelligence platforms. Further updates will be provided as the investigation progresses and additional IOCs are identified.
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
Scanner note: unavailable: raw=connection_error; http=0; via=http_proxy; error=SOCKSHTTPConnectionPool(host='teams-connect-voice.online', port=80): Max retries exceeded with url: / (Caused by NewConn
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Edge-IP reputation is not attributed to this domain.
matt.ns.cloudflare.comviolet.ns.cloudflare.comLocation describes the IP network.
7020861080fa62c5a04c3ec2812001221a0553327cdd5297f29b445795928fdaSaved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
Google PageSpeed Insights — mobile performance audit of teams-connect-voice.online · checked Apr 6, 2026
10 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
Reported by 1 community member, first seen Apr 6, 2026
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Select your country to get official cybercrime contacts, or create a complaint draft →.
Template-based draft · optional AI wording assistance requires separate consent
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowSubmit suspicious domains to our threat database — protect the community
ReportRecent phishing reports and observed availability changes
MonitorMonitor live threats or contest this listing if you believe it's a false positive