teamslivechat[.]us
Сводка доказательств
This domain, teamslivechat.us, is flagged as an active phishing site targeting Microsoft Teams credentials. Registered on April 20, 2026, the domain resolves to 198.54.119.191, an IP address associated with a known hosting provider in the United States. Infrastructure analysis reveals the domain is hosted on a server with a Sectigo-issued SSL certificate, which, while providing encryption, does not validate the legitimacy of the site. The domain appears on three security blocklists and is blocked by multiple threat intelligence platforms, including PhishDestroy, MetaMask, and SEAL, indicating confirmed malicious activity. The domain’s MX records point to mx1-hosting.jellyfish.systems, suggesting potential email capabilities that could be leveraged for further phishing campaigns or credential harvesting. With a trust score of 0/100 and detection by 16 out of 95 security vendors on VirusTotal, the domain exhibits strong indicators of malicious intent. AlienVault OTX further corroborates this assessment, listing the domain in 22 threat intelligence pulses, which often include reports of credential theft or impersonation of collaboration platforms. While the exact content of the site has not been analyzed, the domain name and associated intelligence strongly suggest it is designed to mimic Microsoft Teams login pages or chat interfaces. Defenders should treat this domain as high-risk and prioritize blocking it at the network level, including DNS and web proxy filters. Security teams should also monitor for any attempts to access this domain from internal networks, as such activity may indicate compromised credentials or ongoing phishing attempts. Given the domain’s recent registration and active status, it is likely part of a broader campaign, and defenders should review logs for related indicators of compromise, such as connections to the hosting IP or associated MX records.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 10.08.2026
8 внешних источников под наблюдением Совпадений нет
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание