bakery-swape[.]web[.]app
“BakerySwap”
bakery-swape.web.app — Contenu indisponible. Type d'arnaque : Crypto Scam. Résumé des preuves: VirusTotal 12/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); 1 external blocklist match (ScamSniffer); CF Radar malicious; PhishDestroy score 86/100. Bureau d’enregistrement: Google Domains.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain, bakery-swape.web.app, is flagged as a crypto scam impersonating BakerySwap, a known decentralized finance platform. Analysis indicates the domain was registered through Google LLC and hosted on Firebase infrastructure, resolving to IP 199.36.158.100 (AS54113 Fastly, Inc., US). The SSL certificate is issued by Google Trust Services (WR4), and HTTP Strict Transport Security (HSTS) and HTTP/3 are enabled, suggesting an attempt to appear legitimate. The domain is currently offline, returning an HTTP 404 status, and its nameservers are unresponsive (NS_NOT_FOUND), which may indicate takedown efforts or infrastructure abandonment.
Security vendors have detected malicious activity: 12 of 95 engines on VirusTotal flagged the domain, and it appears on two security blocklists, including PhishDestroy and ScamSniffer. The page title explicitly matches BakerySwap, reinforcing the likelihood of brand impersonation targeting cryptocurrency users. No specific phishing kit or payload has been confirmed in the available data, but the scam type is classified as a crypto scam based on existing intelligence. Defenders should treat this domain as high-risk for crypto-related fraud.
The combination of Firebase hosting, Google registrar, and Fastly IP resolution is consistent with low-cost, disposable infrastructure often used in phishing campaigns. While the domain is offline, historical DNS records and SSL certificate details should be preserved for forensic analysis. Organizations should monitor for re-registration attempts or similar domains using the BakerySwap brand. Blocking access to the IP and domain at the network level is recommended, along with alerting users to potential crypto scam risks associated with this infrastructure.
Signaux de sécurité
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
Technologies · 3 identified
Google platform for building mobile and web applications with backend services.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analyse VirusTotal
Preuves archivées
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif