s[.]teams[.]tl
“403 Forbidden”
Зведення доказів
Analysis of the domain s.teams.tl indicates it was actively flagged as a phishing threat targeting Microsoft Teams users, though it is now offline as of July 23, 2026. The domain was registered on October 3, 2025, through the registrar NETIM and utilized Cloudflare nameservers (christian.ns.cloudflare.com and diana.ns.cloudflare.com), a common tactic to obscure hosting origins and evade takedowns. It resolved to the IP address 172.67.147.192, part of AS13335 (Cloudflare, Inc.), located in the United States. No SSL certificate was detected, increasing the likelihood of interception or manipulation of unencrypted traffic.
At the time of assessment, the domain returned an HTTP 403 Forbidden status, suggesting either deliberate cloaking to avoid analysis or a temporary disruption in service. Detection data from VirusTotal revealed that 13 of 95 security vendors had flagged s.teams.tl as malicious, a moderate but notable consensus given the domain's apparent dormancy. Gridinsoft assigned a trust score of 0/100, further corroborating its classification as high-risk. The domain appeared on at least one security blocklist, and PhishDestroy had previously blocked it, indicating prior active abuse.
The subdomain structure (s.teams.tl) and absence of legitimate branding indicators strongly suggest an intent to deceive users into believing the site was affiliated with Microsoft Teams. However, the exact phishing methodology—whether credential harvesting, malware distribution, or another attack vector—remains unconfirmed due to the lack of accessible page content. Defenders should treat this domain as compromised and maintain blocklist entries to prevent potential reactivation. Monitoring for re-registration or DNS changes is recommended, particularly given the use of Cloudflare infrastructure, which may facilitate rapid redeployment of malicious content.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога