checks-fomo[.]web[.]app
“FOMO - Portfolio Tracker”
checks-fomo.web.app — Non vérifié. Usurpation de l'identité de la marque : Across; Type d'arnaque : Wallet/seed Phishing. Résumé des preuves: VirusTotal 3/91 (alphaMountain.ai, Fortinet, Gridinsoft); 1 external blocklist match (ScamSniffer); PhishDestroy score 70/100. Bureau d’enregistrement: Google Domains.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain, checks-fomo.web.app, is under investigation for brand impersonation targeting Across Protocol, a cross-chain bridging platform. The site presents itself as a legitimate portfolio tracker labeled 'FOMO - Portfolio Tracker,' likely designed to deceive users into entering sensitive credentials or wallet information under false pretenses. Such impersonation attempts are commonly used to harvest login details, private keys, or facilitate unauthorized transactions, posing a direct financial and security risk to visitors. Analysis indicates the domain is hosted on infrastructure associated with Google LLC, resolving to the IP address 199.36.158.100 within the Fastly, Inc. network (AS54113). Despite its active status and operational appearance, the domain has not triggered detections on VirusTotal (0/95 engines), suggesting either recent deployment or deliberate evasion techniques. However, it has been flagged by two independent security blocklists, including PhishDestroy and ScamSniffer, which corroborates suspicions of malicious intent. The SSL certificate, issued by Google Trust Services (WR4), provides encryption but does not validate legitimacy, as fraudulent sites frequently use valid certificates to appear trustworthy. Users who have visited checks-fomo.web.app or interacted with its content should take immediate action to mitigate potential risks. First, disconnect any connected wallets or sessions from the site and revoke any permissions granted via blockchain explorers or wallet interfaces. Monitor accounts for unauthorized transactions and consider transferring assets to a new wallet if credentials were entered. Report the domain to relevant security teams or threat intelligence platforms to aid in broader detection efforts. Exercise caution with unsolicited links, verify domain authenticity through official channels, and enable multi-factor authentication where available to reduce future exposure.
Signaux de sécurité
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 7 identified
Firebase is a Google-backed application development software that enables developers to develop iOS, Android and Web apps.
firebase.google.com Confiance à 100 %Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confiance à 100 %JSDelivr is a free public CDN for open-source projects. It can serve web files directly from the npm registry and GitHub repositories without any configuration.
www.jsdelivr.com Confiance à 100 %HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confiance à 100 %HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confiance à 100 %Analyse VirusTotal
Preuves archivées
Données factuelles et rapports externes
“@triggerpulled”
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif