s[.]teams[.]tl
“403 Forbidden”
s.teams.tl — Conteúdo indisponível (HTTP 502). Tipo de golpe: Generic Phishing. Resumo das evidências: VirusTotal 13/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); PhishDestroy score 89/100. Registrador: NETIM.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of the domain s.teams.tl indicates it was actively flagged as a phishing threat targeting Microsoft Teams users, though it is now offline as of July 23, 2026. The domain was registered on October 3, 2025, through the registrar NETIM and utilized Cloudflare nameservers (christian.ns.cloudflare.com and diana.ns.cloudflare.com), a common tactic to obscure hosting origins and evade takedowns. It resolved to the IP address 172.67.147.192, part of AS13335 (Cloudflare, Inc.), located in the United States. No SSL certificate was detected, increasing the likelihood of interception or manipulation of unencrypted traffic.
At the time of assessment, the domain returned an HTTP 403 Forbidden status, suggesting either deliberate cloaking to avoid analysis or a temporary disruption in service. Detection data from VirusTotal revealed that 13 of 95 security vendors had flagged s.teams.tl as malicious, a moderate but notable consensus given the domain's apparent dormancy. Gridinsoft assigned a trust score of 0/100, further corroborating its classification as high-risk. The domain appeared on at least one security blocklist, and PhishDestroy had previously blocked it, indicating prior active abuse.
The subdomain structure (s.teams.tl) and absence of legitimate branding indicators strongly suggest an intent to deceive users into believing the site was affiliated with Microsoft Teams. However, the exact phishing methodology—whether credential harvesting, malware distribution, or another attack vector—remains unconfirmed due to the lack of accessible page content. Defenders should treat this domain as compromised and maintain blocklist entries to prevent potential reactivation. Monitoring for re-registration or DNS changes is recommended, particularly given the use of Cloudflare infrastructure, which may facilitate rapid redeployment of malicious content.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo