# PhishDestroy threat dossier — teamslives.us ================================================================ Fetched: 2026-07-31 06:22:52 UTC Canonical: https://phishdestroy.io/domain/teamslives.us/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Brand Impersonation Targeted brand: Microsoft ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 15/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, alphaMountain.ai, AlphaSOC, BitDefender, Chong Lua Dao, CRDF, CyRadar, Fortinet, G-Data, Gridinsoft, Kaspersky, Lionic, SOCRadar, Sophos, VIPRE URLQuery: -1 detections AlienVault OTX: 8 pulses (threat-intel feed mentions) Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 198.54.119.191 (US, Dallas) ASN: AS22612 Namecheap, Inc. Hosting org: Namecheap, Inc. Registered: 2026-04-22 Page title: Microsoft Teams meeting | Microsoft Teams HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Sectigo Limited / Sectigo Public Server Authentication CA DV R36 Expires: 2026-11-05 Status: INVALID chain Fingerprint: 94d2ffeafed0241faedbedb271f868e3eea463aa8793149a2c478057aca0af77 Subject Alternative Names (related infrastructure — often same operator): - www.teamslives.us ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-22 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-22 19:30:08 UTC (by PhishDestroy tracker) First reported: 2026-06-15 00:27:29 UTC (abuse notice filed) Last verified: 2026-07-31 08:20:52 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-12 18:03:30 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] teamslives.us: Confirmed Microsoft Teams Brand Impersonation Site Analysis of the domain teamslives.us indicates active brand impersonation targeting Microsoft, specifically mimicking Microsoft Teams meeting pages. The domain was registered on April 22, 2026, and currently resolves to IP address 198.54.119.191, hosted by a provider in the United States. The page title, 'Microsoft Teams meeting | Microsoft Teams,' directly replicates official Microsoft branding, suggesting an intent to deceive users into believing the site is legitimate. Technical indicators reinforce the malicious classification. The domain holds a trust score of 0 out of 100 and appears in 8 threat intelligence pulses, signaling prior detection by security sources. It is blocked by at least three security blocklists, including PhishDestroy, MetaMask, and SEAL. The site returns an HTTP 200 status, confirming active hosting, and uses a Sectigo Limited SSL certificate issued under the Sectigo Public Server Authentication CA DV R36 chain. Despite these red flags, the domain remains undetected by antivirus engines, with 0 out of 95 detections on VirusTotal as of July 12, 2026. Defenders should treat this domain as high-risk due to its confirmed impersonation of Microsoft Teams and its presence on multiple blocklists. The lack of antivirus detections does not indicate safety, as the domain’s infrastructure and behavioral indicators align with phishing campaigns. Network-level blocking is recommended for organizations, particularly those using Microsoft collaboration tools. Monitoring for similar domains registered under the same IP or certificate authority may help identify related threats. No evidence suggests the use of a known phishing kit or affiliation with broader campaign infrastructure. The domain’s creation date and hosting provider are consistent with typical phishing operations, but further forensic analysis would be required to determine the full scope of the threat. Until then, the domain remains an active risk. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 94d2ffeafed0241faedbedb271f868e3eea463aa8793149a2c478057aca0af77 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/teamslives.us/ JSON API: https://api.destroy.tools/v1/check?domain=teamslives.us Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 196,190 domains (84,176 alive under monitoring, 27,265 confirmed neutralized). Site: https://phishdestroy.io