This domain, plether-testnet.web.app, is an active phishing endpoint hosted on Google LLC infrastructure, currently under investigation for generic phishing activity. Infrastructure analysis reveals the domain is registered through Google and resolves to the IP address 199.36.158.100, a Google-owned address space. The domain appears on one security blocklist, specifically PhishDestroy, indicating prior detection by at least one vendor. No nameservers are currently associated with the domain, which may suggest recent provisioning or an incomplete configuration.
The domain remains active as of July 31, 2026, with no additional context regarding the specific phishing kit, targeted brand, or scam type available at this time. Defenders should note that the domain is hosted on Firebase, a legitimate Google service commonly abused for phishing due to its free hosting and association with trusted Google infrastructure. The lack of nameserver records does not preclude malicious activity, as Firebase domains often rely on Google’s internal resolution mechanisms. While only one blocklist currently flags this domain, the absence of additional detections does not confirm safety, as phishing campaigns on newly provisioned endpoints may not yet be widely detected.
Organizations are advised to treat this domain as potentially malicious and consider blocking or monitoring access to it, particularly if internal telemetry indicates user interaction. Further analysis of HTTP headers, SSL certificates, and page content is recommended to determine the exact nature of the phishing attempt. If the domain is linked to a broader campaign, cross-referencing the IP address 199.36.158.100 with other known malicious domains may reveal additional infrastructure. No evidence currently suggests this domain is part of a targeted attack against a specific brand, but defenders should remain vigilant for credential harvesting or malware distribution.