astar-apps[.]web[.]app
Analyse phishing et sécurité de astar-apps.web.app
“Assets | Astar Portal - Astar Network”
astar-apps.web.app — Dernier actif connu (HTTP 200). Usurpation de l'identité de la marque : Discord; Type d'arnaque : Social Media Phishing. Résumé des preuves: VirusTotal 11/91 (ChainPatrol, alphaMountain.ai, BitDefender, CyRadar, Fortinet); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 100/100. Bureau d’enregistrement: Google Domains.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
PhishDestroy has identified a high-risk brand impersonation campaign targeting Discord users through the domain astar-apps.web.app. This domain masquerades as a legitimate Discord-branded portal, specifically mimicking the Astar Network's Assets portal, to deceive users into connecting their cryptocurrency wallets. Once connected, a crypto drainer kit is deployed to steal funds and digital assets. The threat is classified as brand impersonation with a high risk level, and it remains active as of analysis.
Technical indicators paint a clear picture of malicious intent. VirusTotal flags this domain with 7 out of 95 security vendors detecting it as malicious. The domain was registered through Google LLC and resolves to IP address 199.36.158.100. It currently appears on 1 security blocklist, and the page title is "Assets | Astar Portal - Astar Network," furthering the deception. Notably, Google Safe Browsing has not yet flagged this domain, which may allow it to evade initial detection by some users.
As of now, astar-apps.web.app is still active and operational, posing an ongoing risk to Discord users. PhishDestroy recommends avoiding any interaction with this domain and never connecting a cryptocurrency wallet to it. Users who may have been exposed should immediately revoke any permissions granted and transfer assets to a secure wallet. PhishDestroy continues to monitor this threat and will update the advisory if the domain is taken down or escalates further.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 9 identified
Google platform for building mobile and web applications with backend services.
Progressive JavaScript framework for building user interfaces.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comConversion and audience tracking pixel for paid campaigns on X (Twitter) — signals that the site runs paid X ads.
business.x.comHTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comWeb analytics service tracking website traffic and user behavior.
marketingplatform.google.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analyse VirusTotal
Preuves archivées
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif