The domain afx-snapshot.web.app is currently flagged as a generic phishing site and remains active as of the report date, July 31, 2026. Registration records indicate the domain was provisioned through Google LLC, but the authoritative nameserver information is absent, listed as NS_NOT_FOUND, which hampers DNS‑based verification of the hosting environment. Network resolution points to the IP address 199.36.158.100, a host that is known to be shared by multiple web‑app deployments on Google’s Firebase infrastructure.
No additional IP reputation data, such as ASN or geolocation, is supplied in the intelligence set. The domain has been added to at least one external security blocklist and is specifically blocked by the PhishDestroy mitigation service, confirming that at least one third‑party vendor has observed malicious activity associated with this host. No evidence is available concerning SSL certificate details, HTTP response codes, Safe Browsing status, or Open Threat Exchange (OTX) identifiers, leaving those vectors unverified at this time.
The lack of a disclosed page title or content analysis means the exact lure employed by the site cannot be described, though the generic phishing classification suggests attempts to harvest credentials or personal data. Defenders should continue to enforce blocklist rules that include afx-snapshot.web.app, monitor traffic to the associated IP range for anomalous patterns, and consider adding the domain to internal URL filtering policies. Ongoing monitoring of Google’s Firebase hosting changes and periodic re‑inspection of the site’s TLS configuration are recommended to capture any evolution in the threat posture.