Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@hetzner.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
teams[.]cloud-server[.]net[.]in
teams.cloud-server.net.in のフィッシング・安全性チェック
“Welcome to nginx!”
teams.cloud-server.net.in — 最後に確認されたアクティブな状態 (HTTP 200). ブランドの偽装: Microsoft; 詐欺タイプ: Brand Impersonation. 証拠の概要: VirusTotal 7/91 (Cluster25, CRDF, Forcepoint ThreatSeeker, G-Data, Lionic); URLQuery 1 alert; URLScan malicious verdict; PhishDestroy score 85/100. レジストラ: Wild West Domains.
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
Evidence Analysis
This domain, teams.cloud-server.net.in, was identified as a credential theft operation targeting users of Microsoft products, specifically Microsoft Teams. The site masqueraded as an official Microsoft login portal to deceive visitors into entering sensitive account details, such as usernames, passwords, or multi-factor authentication codes. Credential theft sites like this one are commonly used to gain unauthorized access to corporate or personal accounts, leading to data breaches, financial fraud, or further exploitation of connected services. Analysis indicates the domain was flagged by 11 out of 95 security vendors on VirusTotal, a clear indicator of malicious activity. The site was hosted on infrastructure using Nginx, a common web server technology, and employed a Let's Encrypt SSL certificate to appear legitimate. Registration details reveal the domain was registered through Wild West Domains, LLC, though no specific creation date is publicly available. The page title, 'Welcome to nginx!', suggests either a misconfigured or intentionally generic landing page designed to evade initial scrutiny while still capturing credentials. If you visited teams.cloud-server.net.in or entered any login information, immediate action is required. First, change the passwords for any accounts accessed or entered on the site, prioritizing Microsoft accounts and any linked services. Enable multi-factor authentication if not already active, using an authenticator app or hardware key rather than SMS-based methods. Monitor accounts for suspicious activity, such as unauthorized logins or changes to settings, and review connected applications for any unfamiliar third-party access. If corporate credentials were compromised, notify your organization's security team to initiate incident response protocols. Users should also consider running a full scan of their devices for malware, as credential theft sites may deploy additional payloads.
データの網羅性12 recorded checks
ネットワークセキュリティインテリジェンス
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | teams.cloud-server.net.in |
malicious | Sinkholed |
脅威対応 Pipeline
公開ブロックリスト登録状況
使用技術 · 1 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 信頼度 100%VirusTotalによる分析
証拠および外部報告書Independent lookups and source reports
PD-20260610-F687F4 Recipient: abuse@hetzner.com Victim safety and official reportingImmediate actions and verified reporting channels
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。