msmeet[.]us
“Free Online Meetings & Video Calls | Microsoft Teams”
Resumo das evidências
Analysis of the domain msmeet.us, observed as offline as of the report date, shows several indicators consistent with a Microsoft‑related brand‑impersonation campaign. The domain was registered on 27 February 2026 through NameCheap, Inc., and resolves to the IP address 23.254.167.21, which belongs to the Hostwinds LLC network (ASN 54290) located in the United States. No TLS certificate is presented, meaning the site is served over plain HTTP, which reduces the credibility of a legitimate Microsoft service. The authoritative nameservers dns1.registrar-servers.com and dns2.registrar-servers.com are typical of registrar‑provided DNS and do not suggest a custom infrastructure. The page title returned by the now‑taken‑down site reads "Free Online Meetings & Video Calls | Microsoft Teams", directly invoking the Microsoft Teams brand.
The listed brand target is Microsoft, and the documented scam type is a tech‑support scam, indicating that the operator likely attempted to convince victims that their Microsoft account or device required urgent assistance. Detection services have flagged the domain. VirusTotal reports a single positive detection out of 93 scanning engines, and three independent blocklists (PhishDestroy, MetaMask, SEAL) have already listed the domain. The presence on multiple blocklists confirms that security vendors have observed malicious activity associated with the domain.
No SSL certificate, combined with the offline status, suggests the site may have been short‑lived or taken down after detection. Uncertainties remain regarding the exact payload delivered to victims, the extent of any credential harvesting, and whether additional infrastructure (e.g., command‑and‑control servers) is linked to the same IP. Defenders should continue to block msmeet.us at perimeter and DNS layers, monitor for any resurgence of the same IP or registrar‑level registrations, and update detection rules to flag the observed page title and brand‑impersonation pattern.
Instantâneo das evidências enviadas
- Enviado
- Registros do livro-razão
- 1
- ID do caso
PD-20260227-B9CDC6- Título da página capturada
- Free Online Meetings & Video Calls | Microsoft Teams
- Artefato PDF
- Evidência em PDF
Base jurídica
Texto completo da evidência
Policy Violations: Domain Registration Agreement prohibits hacking, misuse of domain to conduct attacks, scam and fraudulent activities; AUP allows immediate suspension
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 12/08/2026
Linha do tempo de detecção
-
VirusTotal
0 → 1
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
-
Status do domínio
Acessível → Inacessível
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo