ellipal-wallets[.]web[.]app
Перевірка домену ellipal-wallets.web.app на фішинг і безпеку
“Hardware Wallet Tutorial | ELLIPAL Titan Cold Wallet Q&A”
ellipal-wallets.web.app — Контент недоступний (HTTP 404). Уособлення бренду: Amazon; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 3/95 (Emsisoft, Netcraft, Webroot); PhishDestroy score 65/100. Реєстратор: Google Domains.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis performed on July 24, 2026 indicates that the domain ellipal-wallets.web.app is currently offline and returns HTTP 404 for the sole observed URL. The page title returned during the scan is "Hardware Wallet Tutorial | ELLIPAL Titan Cold Wallet Q&A", which suggests an attempt to associate the site with the legitimate ELLIPAL hardware‑wallet brand. The domain is hosted on Google Firebase infrastructure, employs HTTP/3 and enforces HSTS, and is served over TLS using a certificate issued by Google Trust Services under the WR4 intermediate. DNS resolution points to the IP address 199.36.158.100, which belongs to AS54113 Fastly, Inc. and is geolocated in the United States.
The hosting provider and CDN configuration are consistent with many legitimate Firebase deployments, but the combination of a 404 response, the "Crypto Scam" classification, and the presence on a security blocklist indicate malicious intent. The domain appears on one blocklist and is listed as blocked by PhishDestroy. VirusTotal analysis shows that three out of ninety‑five scanning engines flagged the domain, reinforcing the suspicion of abuse. Registration details reveal that the domain was provisioned through Google LLC, a common registrar for Firebase‑based sites, which does not provide any protective indication of legitimacy in this context.
No additional evidence such as screenshots, login forms, or malicious payloads were captured during the scan, leaving the exact delivery mechanism of the alleged crypto‑draining activity unknown. Defenders should continue to block the domain at perimeter and DNS layers, monitor for any resurgence of the IP address or related subdomains, and consider adding the host to internal blocklists. Threat intelligence teams should correlate any observed attempts to contact the IP 199.36.158.100 with known crypto‑drain campaigns, and if possible, request additional indicators from the three vendors that reported detections.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
Firebase is a Google-backed application development software that enables developers to develop iOS, Android and Web apps.
firebase.google.com 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога