nodeconnections-v3[.]web[.]app
“Dex Community”
nodeconnections-v3.web.app — Контент недоступний. Тип шахрайства: Crypto Drainer. Зведення доказів: VirusTotal 1/95 (ChainPatrol); PhishDestroy score 55/100. Реєстратор: Google Domains.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of nodeconnections-v3.web.app indicates that the site is currently offline, returning HTTP 404 responses. The domain is hosted on Google’s Firebase platform and serves content over HTTPS with HSTS and HTTP/3 enabled, using a Google Trust Services certificate issued to “WR4”. DNS resolution points to 199.36.158.100, an address owned by Fastly (AS54113) in the United States.
The authoritative nameservers are ns-cloud.googledomains.com, confirming registration through Google LLC. The page title returned by the server is “Dex Community”, which does not correspond to any known legitimate brand and suggests a generic phishing front‑end. VirusTotal records show that one of ninety‑five scanning engines flagged the domain, and the domain appears on a single external blocklist, identified by PhishDestroy as malicious. No additional intelligence such as Safe Browsing or Open Threat Exchange entries is available.
The combination of a Firebase‑based hosting stack, a valid Google‑issued TLS certificate, and the presence of a blocklist entry demonstrates that the domain was actively used for phishing, even though it has been taken offline. Defenders should continue to block the hostname and its IP address in perimeter defenses, monitor for any re‑registration or reuse of the same IP range, and update URL filtering policies to include the observed page title “Dex Community”. Because the domain’s infrastructure components (Firebase hosting, Fastly CDN, Google DNS) are widely used, future phishing campaigns may leverage similar configurations; therefore, security teams should treat any new subdomains under the same registrar or CDN with heightened scrutiny until they are verified.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
Firebase is a Google-backed application development software that enables developers to develop iOS, Android and Web apps.
firebase.google.com 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога