Aller au rapport de sécurité
⚠️
Suspicious Domain — Listed on PhishDestroy
Liste des menaces PhishDestroy stockée. VirusTotal analysis stored; no vendor detections were recorded at check time. Faites preuve d’une extrême prudence – ne saisissez pas d’informations d’identification ou d’informations personnelles.
Sécurité des domaines et renseignements sur les menaces

04-directslots[.]web[.]app

“TronX แตกง่าย - สล็อตเว็บตรง API แท้ 100%”

Verdict de menace Marqué 68/100 score de preuve
Disponibilité Non vérifié L'accessibilité actuelle n'est pas vérifiée
Liste des menaces PhishDestroy stockée Type d'arnaque : Generic Phishing
10/06/2026 CDN

Résumé des preuves

FLAGGED
Evidence score
68/100

This domain, 04-directslots.web.app, has been identified as a generic phishing resource impersonating TronX, a cryptocurrency-based gaming platform. The page title, 'TronX แตกง่าย - สล็อตเว็บตรง API แท้ 100%', explicitly references TronX services, suggesting an attempt to deceive users seeking legitimate gaming or gambling portals. No specific drainer kit signatures have been confirmed at this stage, though the domain exhibits characteristics consistent with credential harvesting or fraudulent transaction redirection schemes targeting Southeast Asian markets. Infrastructure analysis reveals the domain is hosted on Google Firebase, a platform frequently exploited for rapid deployment of phishing resources due to its free tier and SSL provisioning. The domain currently resolves to the IP address 199.36.158.100, a Google Cloud IP range associated with Firebase hosting. VirusTotal detection metrics show 0/95 security vendors flagging the domain as malicious, indicating either a novel campaign or effective evasion techniques. The SSL certificate is issued by Google Trust Services (WR4), providing a veneer of legitimacy. At present, the domain appears on a single security blocklist, PhishDestroy, while Google Safe Browsing has not yet classified it as harmful. The domain remains active and under investigation, with no takedown actions observed as of the latest assessment. The low detection rate combined with the use of reputable hosting infrastructure presents a moderate risk of successful compromise for unprotected users. Organizations are advised to implement network-level blocking for 04-directslots.web.app and the associated IP 199.36.158.100. End users should verify domain authenticity before entering credentials or financial details, particularly when accessing purported gaming or cryptocurrency services. Continuous monitoring of this infrastructure is recommended due to the potential for rapid evolution of the phishing payload.

VirusTotal
VirusTotal
0 det.
Certificat TLS
Google Trust Services
Hosting
Firebase Hosting
Statut observé
Non vérifié
PhishDestroy
DestroyList
Répertorié

Data Coverage

VirusTotal checked — no detections recorded URLQuery pas vérifié PhishStats pas vérifié OTX no community references CF Radar scan completed URLScan capture not submitted URLScan verdict verdict indisponible Blocs DNS 14 vérifié — aucun blocage TLS valid certificate, 69d WHOIS not parsed Capture d'écran 2 captures · 2 sources Chaîne de redirection non sondé
Renseignements sur la sécurité réseau
Free Hosting Detected Firebase Hosting
This domain is hosted on Firebase Hosting (free hosting platform). Free hosting platforms are commonly used for both legitimate testing/development and malicious purposes. Additional context is needed

Processus de réponse aux menaces Pipeline

Découverte
Checks
Reports
Disponibilité
8/10

Couverture des listes de blocage

10 sources externes surveillées · instantané du 12/08/2026

10 sources externes surveillées Aucune correspondance

Capture enregistrée

Informations sur les domaines

Domaine
Serveur / ASN AS54113 Fastly, Inc.
IP Context Fastly shared edge origin IP hidden La réputation Edge-IP n’est pas attribuée à ce domaine.
Fournisseur de plateforme Google Firebase US(US)
Adresse IP 199.36.158.100 CDN
LocalisationUS Mountain View, US
RéseauAS54113 · Google LLC
L'adresse IP d'origine est cachée derrière un proxy CDN. Les résultats d’IP inversé pour l’adresse périphérique contiennent des locataires non liés ; trouver l’origine nécessite un DNS passif ou des données de transparence des certificats.
Détails techniquesDNS, noms TLS et horodatages
Première détection10/06/2026
Submitted URLhttps://04-directslots.web.app/
Empreinte TLS
Observation TLSvalide depuis le 20/05/2026analysé le 13/06/2026
Noms alternatifs du sujet TLSweb.app
Titre de la page
TronX แตกง่าย - สล็อตเว็บตรง API แท้ 100%
Certificat TLS
Valid transport encryption · Émis par Google Trust Services · valid for 69 days
Casino / Gambling License Verification
Unverified gambling license
This domain markets casino/gambling services. Scam casinos routinely display fake Curaçao, MGA, or Kahnawake license badges that don’t exist in the real registries. Always verify the license number against the official regulator database before depositing. If the site shows a seal but no clickable registry link — or the linked registry page doesn’t exist — treat it as fraudulent.
Curaçao eGaming (official) Malta Gaming Authority UK Gambling Commission PA Gaming Control Kahnawake Gaming Gibraltar Gambling

Technologies

6 technologies identifiées avec une forte confiance

Firebase Tailwind CSS HSTS Google Tag Manager Google Analytics HTTP/3
Cloudflare Radar
Signaler ce domaine Envoyez des éléments de preuve et contribuez à protéger les autres

Analyse VirusTotal

0 / Les fournisseurs de sécurité 91 ont signalé ce domaine
View on VT
Last analyzed Previous stored snapshot: 0 detections
No VirusTotal engine marked the domain malicious in the stored analysis.
Analyse des performances du site

Google PageSpeed Insights — mobile performance audit of 04-directslots.web.app · checked Jun 10, 2026

42
Poor
Performance
FCP
3.62s
First Contentful Paint
LCP
14.32s
Largest Contentful Paint
CLS
0.052
Cumulative Layout Shift
TBT
940ms
Total Blocking Time
SI
5.7s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Ce site vous a-t-il affecté ?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.

Europol
Trouvez le canal de signalement officiel pour votre pays de l'UE
National police directory
Méfiez-vous des escrocs qui prétendent vous aider à récupérer vos biens ! Les criminels peuvent recontacter leurs victimes tout en se faisant passer pour des enquêteurs, des avocats ou des agents de recouvrement. Ne payez pas de frais initiaux et ne partagez pas vos informations d'identification. En savoir plus sur la fraude liée aux aides à la reprise →

Signalez-le à vos autorités locales

Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.

Annuaire de 97 pays
Brouillon assisté par l'IA : les détails de l'incident sont traités par le fournisseur d'IA Examinez-le et soumettez-le vous-même

Vérifier n'importe quel domaine

Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique

Scanner maintenant

Signaler une tentative d'hameçonnage

Signalez les domaines suspects à notre base de données des menaces — protégez la communauté

Signaler

Flux d'alertes en temps réel

Rapports de phishing récents et changements de disponibilité observés

Surveiller

Restez informés, restez en sécurité

Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif

Flux d'alertes en temps réel Contester cette annonce

Outils externes

HTML · IFRAME

Intégrer ce rapport

Partagez ces informations sur les menaces sur votre site web ou votre blog

embed.html
<iframe
  src="https://phishdestroy.io/fr/embed/domain/04-directslots.web.app"
  title="PhishDestroy threat report for 04-directslots.web.app"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>