fomo-lookup[.]web[.]app
“FOMO - Portfolio & Airdrops Tracker”
fomo-lookup.web.app — Контент недоступний. Уособлення бренду: Across; Тип шахрайства: Airdrop Scam. Зведення доказів: VirusTotal 4/95 (Emsisoft, Netcraft, Trustwave, Webroot); 4 external blocklist matches; PhishDestroy score 87/100. Реєстратор: Google Firebase.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis dated July 24, 2026 indicates that the sub‑domain fomo-lookup.web.app was provisioned through Google Firebase and served using a Google Trust Services WR4 TLS certificate. The site presented the page title 'FOMO – Portfolio & Airdrops Tracker', a phrasing commonly associated with cryptocurrency airdrop scams. Infrastructure inspection shows the host resolves to 199.36.158.100, an address owned by Fastly, Inc. (ASN 54113) located in the United States. Detected technologies include Firebase hosting, HTTP Strict Transport Security and HTTP/3, confirming a modern CDN‑based deployment.
VirusTotal scans recorded four detections out of ninety‑five AV engines, and the domain appears on five independent blocklists, including PhishDestroy, ScamSniffer, Polkadot, Enkrypt and Codeesura. Scamadviser assigns a trust score of 1 out of 100, reflecting extreme risk. The page currently returns HTTP 404 and the domain has been taken offline, but the historical footprint aligns with a known 'Airdrop Scam' phishing kit that lures victims with promises of free token allocations.
Defenders should continue to block the domain and its associated IP, monitor Fastly edge nodes for similar Firebase‑hosted payloads, and update URL filtering rules to include the observed TLS certificate issuer. Incident response teams are advised to correlate any authentication attempts or wallet address disclosures against the observed page title and kit fingerprint, as compromised credentials are likely to target cryptocurrency portfolios. Ongoing surveillance is recommended because the underlying hosting infrastructure can be rapidly repurposed for new malicious campaigns.
Сигнали безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
Firebase is a Google-backed application development software that enables developers to develop iOS, Android and Web apps.
firebase.google.com 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
“@ace_linkbot”
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога