# PhishDestroy threat dossier — kast-io.web.app ================================================================ Fetched: 2026-04-22 02:41:48 UTC Canonical: https://phishdestroy.io/domain/kast-io.web.app/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Crypto Drainer (wallet extracted) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 10/94 security vendors flagged this domain Flagging vendors: ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar, Emsisoft, G-Data, Kaspersky, Netcraft, Webroot ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 199.36.158.100 (US, Mountain View) ASN: AS54113 Fastly, Inc. Hosting org: Google LLC Registrar: Google LLC Nameservers: NS_NOT_FOUND Registered: 2026-04-04 Page title: Site Not Found HTTP response: 404 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WR4 Expires: 2026-06-18 Status: INVALID chain Fingerprint: 38e3c92d485d84e61795f095cb3c5f8db07098cd4faa453f265668221022a6fc Subject Alternative Names (related infrastructure — often same operator): - web.app ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-04 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-04 15:30:11 UTC (by PhishDestroy tracker) Last verified: 2026-04-21 16:09:10 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019d5875-3ee1-7660-a42a-a495e9595483/ Wayback Machine: https://web.archive.org/web/*/kast-io.web.app crt.sh CT logs: https://crt.sh/?q=%25.kast-io.web.app Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=kast-io.web.app AlienVault OTX: https://otx.alienvault.com/indicator/domain/kast-io.web.app URLhaus: https://urlhaus.abuse.ch/host/kast-io.web.app/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-04 15:38:42 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies kast-io.web.app as an active crypto drainer phishing domain registered through Google LLC and currently resolving to IP 199.36.158.100. This domain employs a generic phishing vector to deceive users into connecting cryptocurrency wallets under the false pretense of legitimate services, with the malicious infrastructure hosted on Google’s Firebase platform to evade traditional detection mechanisms. While the precise drainer kit remains unverified due to zero detections on VirusTotal as of seed 9ca4d0, the use of Firebase suggests an attempt to exploit trusted domains for credential theft or wallet draining operations. Technical indicators confirm the following: VirusTotal detection score is 0/95 engines, domain registered via Google LLC, IP resolution to 199.36.158.100, SSL certificate issued by Google Trust Services, and domain creation timestamp remains undetermined due to Firebase’s dynamic subdomain handling. The domain is not currently flagged in Google Safe Browsing (GSB) and has no known listings on public blocklists as of investigation seed 9ca4d0. Despite the absence of immediate detections, the infrastructure’s reliance on Google’s ecosystem introduces plausible deniability and operational longevity. This domain remains active and under investigation with a status of 'under_investigation' and risk level categorized as 'high' due to the potential for real-time asset exfiltration. Organizations and users are advised to block kast-io.web.app at the network and endpoint levels, avoid interaction, and report the domain to threat intelligence platforms and browser security vendors. Remaining risk is mitigated only through proactive blocking, as the domain’s Firebase hosting and SSL certification by Google Trust Services reduce immediate visibility for automated defenses. Continuous monitoring of wallet drainer IOCs is recommended to prevent exposure. [Updates since narrative was generated:] - VirusTotal detections: now 10/94 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 38e3c92d485d84e61795f095cb3c5f8db07098cd4faa453f265668221022a6fc ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/kast-io.web.app/ JSON API: https://api.destroy.tools/v1/check?domain=kast-io.web.app Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io