solidity-compiler-v1-8-4[.]web[.]app
“Solidity Compiler - Smart-Contract Compiler for EVM & ERC-20 Developers”
solidity-compiler-v1-8-4.web.app — 콘텐츠를 사용할 수 없음. 브랜드 사칭: Google; 사기 유형: Brand Impersonation. 증거 요약: VirusTotal 2/91 (alphaMountain.ai, Forcepoint ThreatSeeker); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. 등록기관: Google Domains.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
The domain solidity-compiler-v1-8-4.web.app is currently active and confirmed to host a crypto drainer phishing campaign. This site impersonates the Solidity compiler, a critical tool for Ethereum Virtual Machine (EVM) and ERC-20 smart contract developers. The page title, 'Solidity Compiler - Smart-Contract Compiler for EVM & ERC-20 Developers,' is designed to deceive developers into interacting with malicious smart contracts or disclosing private keys, leading to unauthorized asset transfers. Analysis indicates the domain was registered on June 14, 2026, through Google LLC, a legitimate registrar often exploited for hosting malicious content under its web.app subdomain service. The domain resolves to the IP address 199.36.158.100, a host associated with prior phishing activity. Security vendors have flagged this domain, with 2 out of 95 VirusTotal engines detecting it as malicious. Additionally, the domain appears on three security blocklists, including high-confidence threat intelligence feeds. The SSL certificate, issued by Google Trust Services (WR4), provides a false sense of security, as it is automatically provisioned for all web.app domains. As of the latest verification, the phishing site remains active and continues to pose a significant risk to developers and cryptocurrency users. It is strongly recommended to block the domain and its associated IP address at the network level. Users should verify the authenticity of any Solidity compiler tools by accessing them exclusively through official repositories or verified documentation. Organizations are advised to update their threat intelligence feeds to include this domain and monitor for related indicators of compromise, such as wallet addresses or contract interactions linked to this campaign.
위협 대응 Pipeline
공개 차단 목록 상태
사용 기술 · 3 identified
Firebase is a Google-backed application development software that enables developers to develop iOS, Android and Web apps.
firebase.google.com 신뢰도 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 신뢰도 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 신뢰도 100%VirusTotal 분석
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.