MALICIOUS — CRITICAL
teams-room[.]cloud
9 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL); the latest stored check returned HTTP 502.
- VirusTotal
- 9/91
- Blocklists
- 2 · MetaMask, SEAL
- Доступность
- Контент недоступен · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
teams-room.cloud — Контент недоступен (HTTP 502). Сводка доказательств: VirusTotal 9/91 (alphaMountain.ai, BitDefender, CRDF, Forcepoint ThreatSeeker, Fortinet); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 90/100. Регистратор: Namecheap.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
The domain teams-room.cloud was registered through Namecheap Inc and created on July 17, 2026. It is delegated to the authoritative name servers dns1.registrar-servers.com and dns2.registrar-servers.com and currently resolves to the IPv4 address 162.255.119.197. As of the report date, July 20, 2026, the domain remains active and is classified as a high‑risk generic phishing campaign. Threat intelligence indicates that the domain is listed on three security blocklists—PhishDestroy, MetaMask, and SEAL—demonstrating that multiple providers have observed malicious activity associated with the host. No public content analysis or page‑level indicators have been published, so the exact phishing lure, targeted brand, or credential‑capture tactics remain unknown. Defenders should proactively block traffic to 162.255.119.197 and to the domain name, add teams-room.cloud to internal deny lists, and monitor DNS queries for any anomalous resolution patterns. Continuous observation of the associated name servers and periodic re‑lookup of the IP address are recommended to detect possible infrastructure changes. Given the high‑risk rating and active blocklist presence, immediate containment actions are advised while further forensic investigation is conducted.
Охват данных12 recorded checks
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | teams-room.cloud |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчетыIndependent lookups and source reports
PD-20260720-AA4382 Recipient: abuse@namecheap.com Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.