plether-testnet.firebaseapp.com is classified critical with an evidence score of 74/100. 0 of 91 security engines flagged the domain; 3 public blocklists listed it (MetaMask, ScamSniffer, SEAL). Registration metadata recorded via Google LLC, hosted on 199.36.158.100 (Fastly, Inc., US). The latest stored check on 9 Aug 2026 returned HTTP 404 and includes a capture.
Stored generated summary (templated)cerebras · 31/07/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
Analysis of the domain plether-testnet.firebaseapp.com, observed on July 31, 2026, indicates that it is actively being used for malicious activity classified as generic phishing. The domain is registered through Google LLC and resolves to the IP address 199.36.158.100. Infrastructure monitoring shows that the domain is listed on a single security blocklist and has been explicitly blocked by the PhishDestroy mitigation service.
The current operational status is reported as active, suggesting that the phishing infrastructure remains online and capable of delivering fraudulent content. Nameserver information is unavailable (NS_NOT_FOUND), limiting visibility into the authoritative DNS configuration and complicating further attribution efforts. No additional intelligence such as SSL certificate details, HTTP response codes, Safe Browsing verdicts, or external analysis from platforms like OTX is present in the available data, leaving those aspects of the threat profile unverified.
Defensive teams should prioritize the inclusion of the IP 199.36.158.100 and the domain plether-testnet.firebaseapp.com in network‑level blocklists and endpoint protection rules. Continuous monitoring of the domain’s resolution patterns and any emergence of new blocklist entries is advised, as changes could indicate escalation or diversification of the phishing campaign. Organizations that rely on Google‑hosted services should verify that internal redirects or OAuth flows are not being abused by this domain, and users should be warned against interacting with any unsolicited communications that reference the domain.