Analysis of simplescratchdesk.firebaseapp.com shows the domain remains active as of the report date, July 28, 2026. The domain is hosted on Firebase, with registration recorded under Google LLC, and resolves to the IP address 199.36.158.100. No nameserver records were returned, which is consistent with the default configuration for Firebase‑hosted sites.
The infrastructure appears on three public security blocklists and is explicitly blocked by the PhishDestroy, MetaMask, and SEAL filtering services, indicating that multiple independent threat‑intel feeds have flagged the host for malicious use. VirusTotal reports that the domain was scanned by 91 antivirus and URL‑reputation engines, none of which raised a detection at the time of scanning; this absence of alerts does not constitute a validation of safety and should be interpreted as a lack of current vendor signatures rather than evidence of legitimacy. No public SAFE Browsing, OTX, or other reputation feeds are cited in the available data, and details such as SSL certificate validity, HTTP response codes, page title, or content snapshots have not been disclosed, leaving those aspects of the site unverified.
Given the confirmed presence on multiple blocklists, the association with a known phishing‑blocking service, and the active hosting configuration, defenders should treat the domain as high‑risk. Recommended actions include adding the domain to internal deny lists, ensuring that web‑filtering appliances deny traffic to 199.36.158.100, and monitoring for any related subdomains or redirects that may be used in credential‑harvesting campaigns. Continuous re‑scanning with sandbox and URL‑reputation services is advised to capture any future payload changes or new vendor detections.