Analysis of plether-fi.firebaseapp.com (report date July 31, 2026) shows that the host resolves to the IPv4 address 199.36.158.100, which is owned by Google LLC. Registration information indicates the domain was provisioned through Google’s infrastructure, and no distinct nameserver records are returned (NS_NOT_FOUND). The domain is currently listed on a single security blocklist and has been flagged by the PhishDestroy vendor as active. No additional public threat intelligence sources such as OTX or Safe Browsing entries are cited in the supplied data.
The limited observable footprint consists of the IP resolution, registrar details, and blocklist status; content‑level attributes such as page title, SSL certificate, HTTP response codes, or brand targeting have not been disclosed. Consequently, the exact malicious payload or impersonated service cannot be confirmed at this time.
Defenders should continue to block traffic to the domain, monitor DNS queries for the IP 199.36.158.100, and enforce existing web‑filtering policies that reference the identified blocklist entry. Further investigation, including a manual retrieval of the landing page and analysis of any submitted credentials, is recommended to determine the scope of the campaign and to enrich detection signatures.