Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@teaminternet.com.
The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
team[.]asn[.]lv
“asn.lv”
team.asn.lv — 未验证. 品牌冒充:Microsoft; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 6/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, Kaspersky); URLQuery 7 alerts; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 82/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Risk level under_investigation – Microsoft 365 credential phishing site active
PhishDestroy identifies team.asn.lv as a live Microsoft 365 credential harvesting domain that masquerades as a legitimate team or business login portal. The lure preys on users expecting a routine Office 365 authentication prompt, aiming to steal corporate email and document credentials without raising immediate suspicion.
This domain was flagged by PhishDestroy seed 64b514 with current VirusTotal coverage at 0 detections from 95 engines, resolution to hostile IP 185.53.179.128, and registrar details pending further enumeration. Creation fingerprint and blocklist inclusion remain under continued analysis while trust scores trend near zero due to absence of reputable categorization or prior sightings in threat intelligence feeds.
Mitigation for this Microsoft 365 credential phishing attack requires immediate defensive actions: block inbound DNS resolution to 185.53.179.128 at perimeter resolvers, flag team.asn.lv in email security gateways for URL rewriting or message quarantine, and deploy user awareness training highlighting suspicious login prompts outside corporate SSO portals. If compromise is suspected, force password resets for impacted accounts and audit recent OAuth grants and email forwarding rules for signs of data exfiltration.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | obseu.northwavepoint.com |
malicious | Sinkholed |
| DigiCert UltraDNS | l.cdn-fileserver.com |
malicious | Sinkholed |
| Quad9 DNS | l.cdn-fileserver.com |
malicious | Sinkholed |
| DNS4EU | realtimesearchresults.com |
malicious | Sinkholed |
| Cloudflare DNS | realtimesearchresults.com |
malicious | Sinkholed |
| DigiCert UltraDNS | s.cdn-fileserver.com |
malicious | Sinkholed |
| DigiCert UltraDNS | euob.northwavepoint.com |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of team.asn.lv · checked May 14, 2026
证据与外部报告
PD-20260514-52773B Recipient: abuse@teaminternet.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。