Scan report · 26 days agoPublic

msteams.zioum.xyz

95.182.84.234AS211273 · CZ

page delivers an executable (https://msteams.zioum.xyz/MsTeams_Update.iso)

brand impersonation (Microsoft, high)
Engine tags
Verdict

What happened

Step by step, from what the scanner recorded.
Load 1.2 s · 9 requests
01 · Visitor opensmsteams.zioum.xyz/mstore.html
02 · Page shown
Microsoft Store - Microsoft Teamsstyled as Microsoft · high
03 · File delivered · suspiciousMsTeamsInstaller_x64_x32.cmdmsteams.zioum.xyzHanded over by the page, not served at the scanned address.
04 · OutcomeCredential phishingA login page wearing a brand it does not own.

Be careful — warning signs found

Automated

It presents itself as Microsoft while being hosted somewhere Microsoft does not own. This site shows signs commonly seen in scams or impersonation, but we could not confirm it for certain. It may be a real threat, or it may be a legitimate site that simply looks unusual to our automated checks.

What to do

Avoid entering passwords or payment details until you are sure it is genuine. Open the company directly from its known website or app instead of this link. Check the evidence below and escalate to your analyst if unsure.

"Suspicious" is a caution, not a confirmation — it can be a false alarm. The evidence below explains why it was flagged.

Findings

Strongest first
Suspicious fileSuspicious content in the downloaded file
MsTeamsInstaller_x64_x32.cmd

We analysed the file this page delivered — it is Suspicious.

Success

SHA-256 a49ab13a5fcf0a066b7f589cb6278bfdd344d03d95cf8e3d8546028735e1fd9e

SupportingPage delivers an executable under a document pretext
https://msteams.zioum.xyz/MsTeams_Update.iso · brand impersonation (Microsoft, high)

The page presents itself as a document but its button downloads a program to run, not a document to read.

Analyst noteConfirm what the download actually serves. A document workflow that delivers an installer is the tell; the file itself may be signed and clean.

SupportingBrand impersonation detected
Microsoft · high

The page presents itself as a known brand (brand keywords/branding detected).

Analyst noteHigh confidence: brand keywords AND a password field — classic credential phishing.

File

Stored by the engine

What you download may be live malware. Open it only in an isolated environment, and do not double-click it.

The ZIP is encrypted. Password:infected

Inside the ZIP the file carries a name the engine generated, not the one the page used.

Delivered fileSuspiciousMsTeamsInstaller_x64_x32.cmd

SHA-256a49ab13a5fcf0a066b7f589cb6278bfdd344d03d95cf8e3d8546028735e1fd9e

Fromhxxps://msteams[.]zioum[.]xyz/MsTeams_Update[.]iso

Infrastructure

IP
95.182.84.234csoft - Cloud Software - FZCO, AE · AS211273CZ
TLS
CN=YR1, O=Let's Encrypt, C=US · expires Nov 11, 2026

WHOIS

Registrar
PDR Ltd. d/b/a PublicDomainRegistry.com
Created
Feb 23, 2026
Expires
Feb 23, 2027
Nameservers
aleena.ns.cloudflare.commustafa.ns.cloudflare.com
19 malicious124 suspicious

Hashes & fingerprints

Page capture

Live

Title “Microsoft Store - Microsoft Teams” · brand shown: Microsoft (high)

Engines

9 · time to verdict

Page

HTTP
200 · Completed
Title
Microsoft Store - Microsoft Teams
Load
1.23 s · 9 requests
Stack · 4Cloudflare Browser InsightsHSTSHTTP/3Nginx