Analysis of the subdomain instantjotlab.firebaseapp.com, observed on 30 July 2026, indicates that it is actively employed in a generic phishing campaign. The domain is registered through Google LLC, leveraging the Firebase hosting platform, and resolves to the IPv4 address 199.36.158.100. Infrastructure examination reveals that the hosting IP is associated with Google Cloud services, a common vector for malicious actors due to the trust afforded to Google‑owned endpoints. The site remains online at the time of analysis, confirming its active status.
Multiple security vendors have taken mitigation actions: PhishDestroy, MetaMask, and SEAL have each listed the domain in their blocklists, and the domain appears on three independent security blocklists. This multi‑vendor detection reinforces the assessment of high risk. The registrar information confirms that the subdomain is under the control of Google LLC, and the nameserver query returned NS_NOT_FOUND, indicating that standard DNS delegation data is not publicly exposed for this particular sub‑domain. No publicly available page title or content snapshot has been retrieved, and therefore the exact visual or textual lure employed by the site cannot be described at this time.
Nonetheless, the presence of the domain on established phishing blocklists, combined with its active resolution to a Google‑owned IP, satisfies the criteria for a confirmed phishing infrastructure. Defenders are advised to continue blocking the domain at perimeter firewalls, DNS resolvers, and endpoint protection solutions, and to monitor outbound connections for attempts to contact the IP address 199.36.158.100. Further investigation should include automated retrieval of the HTTP response, TLS certificate inspection, and correlation with any credential harvesting activity observed within the organization.