MALICIOUS — CRITICAL
smartgenprotal[.]web[.]app
Domain smartgenprotal.web.app is assessed as a high-risk brand impersonation infrastructure targeting the Base ecosystem.
- VirusTotal
- 3/91
- Blocklists
- 3 · MetaMask, ScamSniffer
- Kullanılabilirlik
- Bilinen son aktif · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
smartgenprotal.web.app — Bilinen son aktif (HTTP 200). Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 3/91 (alphaMountain.ai, Fortinet, Gridinsoft); 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 89/100. Kayıt kuruluşu: Google Domains.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
Domain smartgenprotal.web.app is assessed as a high-risk brand impersonation infrastructure targeting the Base ecosystem. The page currently displays a generic landing interface (“Welcome to our website”) consistent with early-stage phishing deployment or template staging used to support credential capture or wallet interaction abuse. The impersonation objective is to mimic trusted Web3 infrastructure to induce user interaction under false legitimacy.
Technical telemetry indicates VirusTotal detection rate of 0/95, meaning no automated antivirus vendors currently flag the domain, despite its inclusion on 4 independent security blocklists. The domain was created on April 30, 2026 and is registered through Google LLC. It resolves to IP 199.36.158.100 and is hosted under US-based Google LLC infrastructure. TLS is issued via Google Trust Services certificate (WR4). The combination of low detection coverage and multiple blocklist appearances suggests recently deployed malicious infrastructure evading signature-based detection.
The domain remains active, increasing exposure risk for users interacting with Base-related services or decentralized application prompts. Immediate mitigation includes blocking DNS resolution for smartgenprotal.web.app, enforcing Web3 wallet interaction restrictions for unknown domains, and monitoring network traffic to 199.36.158.100. Users should avoid connecting wallets or signing any transactions on this site. Given active status, fresh registration, and confirmed blocklist presence, the threat remains viable despite zero VirusTotal detections, requiring behavior-based detection and proactive blocking rules.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 7 identified
Firebase is a Google-backed application development software that enables developers to develop iOS, Android and Web apps.
firebase.google.com %100 güvenCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenJSDelivr is a free public CDN for open-source projects. It can serve web files directly from the npm registry and GitHub repositories without any configuration.
www.jsdelivr.com %100 güvenHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.