firebasestorage.googleapis.com
Checking live DNS resolution...
100/100
CRITICAL RISK
90
Malware URLs
15
Resolved IPs
28
Abuse Reports
40
Active URLs

Threat Intelligence Summary: firebasestorage.googleapis.com

Risk Level: CRITICALThreat Score: 100/100

Assessment: firebasestorage.googleapis.com is actively hosting 40 malware URLs across 15 resolved IP addresses. The number of active endpoints suggests ongoing, organized malware distribution. This domain should be blocked at the DNS or firewall level. Malware families associated with this domain include AgentTesla, hta, VIPKeylogger.

Recommendation: Block immediately at DNS and firewall level


Total Malware URLs: 90 — Active: 40 — Resolved IPs: 15 — Abuse Reports: 28

First Seen: 2025-09-19T06:56:08 — Last Online: 2026-07-27T01:36:05

Data aggregated from threat intelligence feeds including URLhaus and community reports.

Domain Threat Analysis

firebasestorage.googleapis.com has been associated with 90 malware URLs , of which 40 are currently active . The primary threat types are malware_download.

Active threat. This domain is currently serving malicious content. Multiple malware URLs have been identified on this domain. Network administrators should consider blocking this domain or monitoring traffic to it closely.

Associated malware families include: AgentTesla.

Look Up Another Domain or IP

Check any domain or IP address against our threat intelligence database.

Access This Data via API

Integrate WAYSCloud domain threat intelligence into your security tools, SIEM, or firewall rules. Query any domain programmatically for malware URLs, resolved IPs, and threat scores.

API Documentation Integration Guide

See how we classify and verify threats →

Related Threat Intelligence

Top Threats Today Latest Attacks Active Malware Domains Understanding Botnets SSH Attack Explainer How to Block Threats What is a Phishing Domain? About Malware Distribution Check Another Domain
Timeline
First Seen
2025-09-19T06:56:08
Last Seen Online
2026-07-27T01:36:05
Data Last Updated
2026-07-27T05:00:15.162809
Status Activity Timeline (50 changes recorded)

Complete history of all status changes detected for URLs on this domain. Tracking online/offline transitions helps identify malware lifecycle patterns.

OFFLINE
https://firebasestorage.googleapis.com/v0/b/dropfile-ff5b9-j0mm4/o/lovethiursdayLincoln.ps1?alt=media&token=b1fba6a1-799d-4b8b-8b14-d48f34e19bba
First detected as offline
OFFLINE
https://firebasestorage.googleapis.com/v0/b/dropfile-ff5b9-j0mm4/o/day1mondasyLincoln.txt?alt=media&token=975f86e4-4fbf-4963-84df-9d68ea0a1dc3
First detected as offline
OFFLINE
https://firebasestorage.googleapis.com/v0/b/june-july-dd5c8-91uk3/o/22mondayLincoln.txt?alt=media&token=ce3b0c87-e670-4b32-940c-675bdc4fc8d2
First detected as offline
OFFLINE
https://firebasestorage.googleapis.com/v0/b/dropfile-ff5b9/o/FRIDAYLincoln.txt?alt=media&token=839d459b-c819-45c5-8748-9e7d70ba4570
First detected as offline
ONLINE
https://firebasestorage.googleapis.com/v0/b/june-july-dd5c8/o/Cytophil.exe?alt=media&token=cb9fe647-a483-4d59-93e6-c044948eb453
First detected as online
ONLINE OFFLINE
https://firebasestorage.googleapis.com/v0/b/rodriakd-8413d.appspot.com/o/dll%2FMSBuild.txt?alt=media&token=984ee921-1647-4fd6-a4df-ef3e9fea927b
Status changed from online to offline
ONLINE OFFLINE
https://firebasestorage.googleapis.com/v0/b/rodriakd-8413d.appspot.com/o/dll%2F1%20link%20dll.txt?alt=media&token=e7389ad2-4ad9-4fb7-bf60-2a502bbb6c6c
Status changed from online to offline
ONLINE
https://firebasestorage.googleapis.com/v0/b/rodriakd-8413d.appspot.com/o/dll%2F1%20link%20dll.txt?alt=media&token=e7389ad2-4ad9-4fb7-bf60-2a502bbb6c6c
First detected as online
ONLINE
https://firebasestorage.googleapis.com/v0/b/rodriakd-8413d.appspot.com/o/dll%2FMSBuild.txt?alt=media&token=984ee921-1647-4fd6-a4df-ef3e9fea927b
First detected as online
OFFLINE
https://firebasestorage.googleapis.com/v0/b/remasd-6c702.firebasestorage.app/o/frost%2Fpic2.jpg?alt=media&token=589f956e-d019-4472-a000-29f8eb203489
First detected as offline
OFFLINE
https://firebasestorage.googleapis.com/v0/b/maty-60fd2.firebasestorage.app/o/WEDLincoln.ps1?alt=media&token=176a0671-0105-4b5a-b16b-47bb323baf6b
First detected as offline
ONLINE OFFLINE
https://firebasestorage.googleapis.com/v0/b/rodriakd-8413d.appspot.com/o/dll%2Fcaca.txt?alt=media&token=08d47962-34f1-4c6c-833e-ffaee91128c2
Status changed from online to offline
ONLINE OFFLINE
https://firebasestorage.googleapis.com/v0/b/rodriakd-8413d.appspot.com/o/Pe%2Fperoda.txt?alt=media&token=19f18e11-cd02-4a4c-baca-8d4fc54ac6a8
Status changed from online to offline
ONLINE OFFLINE
https://firebasestorage.googleapis.com/v0/b/rodriakd-8413d.appspot.com/o/dll%2Fdll%20newaaaaaaaaa.txt?alt=media&token=92418096-85c5-4090-a574-5c807c304562
Status changed from online to offline
ONLINE OFFLINE
https://firebasestorage.googleapis.com/v0/b/jsee-71d18.firebasestorage.app/o/img_170600.png?alt=media&token=0dc575d2-44f3-40b2-ba8e-b397383f766d
Status changed from online to offline
ONLINE
https://firebasestorage.googleapis.com/v0/b/rodriakd-8413d.appspot.com/o/dll%2Fdll%20newaaaaaaaaa.txt?alt=media&token=92418096-85c5-4090-a574-5c807c304562
First detected as online
OFFLINE
https://firebasestorage.googleapis.com/v0/b/rodriakd-8413d.appspot.com/o/dll%2Fjs.txt?alt=media&token=09ada575-efa9-4dc8-b331-404723b5997a
First detected as offline
OFFLINE
https://firebasestorage.googleapis.com/v0/b/rodriakd-8413d.appspot.com/o/dll%2Fdllnew.txt?alt=media&token=630e2807-b89c-4645-b3dc-dc407ccae141
First detected as offline
ONLINE
https://firebasestorage.googleapis.com/v0/b/jsee-71d18.firebasestorage.app/o/img_170600.png?alt=media&token=0dc575d2-44f3-40b2-ba8e-b397383f766d
First detected as online
ONLINE
https://firebasestorage.googleapis.com/v0/b/spenglercomics.firebasestorage.app/o/task.txt?alt=media&token=f162f5ce-52f7-4407-8cc4-dd96cedd9b0e
First detected as online
Showing 20 most recent changes of 50 total
Associated IP Addresses (15)

All IP addresses this domain has resolved to (current and historical). These IPs may host or have hosted malware URLs.

209.85.203.95
0 abuse reports
216.239.34.223
5 abuse reports Severity: high
172.217.19.234
4 abuse reports Severity: high
216.239.32.223
5 abuse reports Severity: high
172.217.117.4
5 abuse reports Severity: high
172.217.21.170
0 abuse reports
142.251.142.234
2 abuse reports Severity: high
142.250.74.10
0 abuse reports
216.58.207.202
0 abuse reports
172.253.116.95
0 abuse reports
142.251.38.106
2 abuse reports Severity: high
216.58.207.234
0 abuse reports
142.250.74.106
0 abuse reports
216.58.201.234
0 abuse reports
216.239.38.223
5 abuse reports Severity: high
Malware Classification
AgentTesla
Popular since 2014, this .NET-based keylogger evolved into sophisticated spyware. Exfiltrates credentials via SMTP, FTP, or Telegram. Favored by less technical attackers due to builder tools that require no programming knowledge.
hta
Malware family "hta" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
VIPKeylogger
Malware family "VIPKeylogger" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
jpg-base64-loader
Malware family "jpg-base64-loader" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
stego
Malware family "stego" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
base64
Malware family "base64" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
ArkanixStealer
Malware family "ArkanixStealer" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
PhantomStealer
Malware family "PhantomStealer" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
powershell
Malware family "powershell" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
dcrat
Malware family "dcrat" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
Malware URLs (90)

All malicious URLs identified on this domain. Status reflects last known state from threat intelligence feeds.

https://firebasestorage.googleapis.com/v0/b/dropfile-ff5b9-j0mm4/o/lovethiursdayLincoln.ps1?alt=media&token=b1fba6a1-799d-4b8b-8b14-d48f34e19bba
Taken Down
IP: 172.217.117.4
Type: malware_download
First Seen: 2026-07-24
AgentTesla
https://firebasestorage.googleapis.com/v0/b/dropfile-ff5b9/o/FRIDAYLincoln.txt?alt=media&token=839d459b-c819-45c5-8748-9e7d70ba4570
Taken Down
IP: 172.217.117.4
Type: malware_download
First Seen: 2026-07-22
AgentTesla
https://firebasestorage.googleapis.com/v0/b/dropfile-ff5b9-j0mm4/o/day1mondasyLincoln.txt?alt=media&token=975f86e4-4fbf-4963-84df-9d68ea0a1dc3
Taken Down
IP: 172.217.117.4
Type: malware_download
First Seen: 2026-07-22
AgentTesla
https://firebasestorage.googleapis.com/v0/b/june-july-dd5c8-91uk3/o/22mondayLincoln.txt?alt=media&token=ce3b0c87-e670-4b32-940c-675bdc4fc8d2
Taken Down
IP: 172.217.117.4
Type: malware_download
First Seen: 2026-07-22
AgentTesla
https://firebasestorage.googleapis.com/v0/b/june-july-dd5c8/o/Cytophil.exe?alt=media&token=cb9fe647-a483-4d59-93e6-c044948eb453
Active Threat
IP: 172.217.117.4
Type: malware_download
First Seen: 2026-07-21
AgentTesla exe
https://firebasestorage.googleapis.com/v0/b/rodriakd-8413d.appspot.com/o/dll%2FMSBuild.txt?alt=media&token=984ee921-1647-4fd6-a4df-ef3e9fea927b
Taken Down
IP: 216.239.32.223
Type: malware_download
First Seen: 2026-05-27
base64 base64-loader Encoded opendir rat vbs
https://firebasestorage.googleapis.com/v0/b/rodriakd-8413d.appspot.com/o/dll%2F1%20link%20dll.txt?alt=media&token=e7389ad2-4ad9-4fb7-bf60-2a502bbb6c6c
Taken Down
IP: 216.239.32.223
Type: malware_download
First Seen: 2026-05-27
base64-loader dcrat opendir vbs
https://firebasestorage.googleapis.com/v0/b/remasd-6c702.firebasestorage.app/o/frost%2Fpic2.jpg?alt=media&token=589f956e-d019-4472-a000-29f8eb203489
Taken Down
IP: 216.239.38.223
Type: malware_download
First Seen: 2026-05-21
rat RemcosRAT
https://firebasestorage.googleapis.com/v0/b/maty-60fd2.firebasestorage.app/o/WEDLincoln.ps1?alt=media&token=176a0671-0105-4b5a-b16b-47bb323baf6b
Taken Down
IP: 216.239.34.223
Type: malware_download
First Seen: 2026-05-19
None
https://firebasestorage.googleapis.com/v0/b/rodriakd-8413d.appspot.com/o/dll%2Fdll%20newaaaaaaaaa.txt?alt=media&token=92418096-85c5-4090-a574-5c807c304562
Taken Down
IP: 172.253.116.95
Type: malware_download
First Seen: 2026-04-17
ascii base64-loader Encoded
https://firebasestorage.googleapis.com/v0/b/rodriakd-8413d.appspot.com/o/dll%2Fjs.txt?alt=media&token=09ada575-efa9-4dc8-b331-404723b5997a
Taken Down
IP: 172.253.116.95
Type: malware_download
First Seen: 2026-04-15
base64-loader Formbook
https://firebasestorage.googleapis.com/v0/b/rodriakd-8413d.appspot.com/o/dll%2Fdllnew.txt?alt=media&token=630e2807-b89c-4645-b3dc-dc407ccae141
Taken Down
IP: 172.253.116.95
Type: malware_download
First Seen: 2026-04-15
base64-loader
https://firebasestorage.googleapis.com/v0/b/jsee-71d18.firebasestorage.app/o/img_170600.png?alt=media&token=0dc575d2-44f3-40b2-ba8e-b397383f766d
Taken Down
IP: 172.253.116.95
Type: malware_download
First Seen: 2026-04-14
AgentTesla
https://firebasestorage.googleapis.com/v0/b/spenglercomics.firebasestorage.app/o/task.txt?alt=media&token=f162f5ce-52f7-4407-8cc4-dd96cedd9b0e
Active Threat
IP: 142.251.38.106
Type: malware_download
First Seen: 2026-04-09
ascii AsyncRAT rev-base64-loader
https://firebasestorage.googleapis.com/v0/b/rodriakd-8413d.appspot.com/o/dll%2Fcaca.txt?alt=media&token=08d47962-34f1-4c6c-833e-ffaee91128c2
Taken Down
IP: 209.85.203.95
Type: malware_download
First Seen: 2026-03-24
base64-loader
https://firebasestorage.googleapis.com/v0/b/rodriakd-8413d.appspot.com/o/Pe%2Fperoda.txt?alt=media&token=19f18e11-cd02-4a4c-baca-8d4fc54ac6a8
Taken Down
IP: 209.85.203.95
Type: malware_download
First Seen: 2026-03-24
ascii rev-base64-loader
https://firebasestorage.googleapis.com/v0/b/mis-archivos-2026-4b0c7.firebasestorage.app/o/class.txt?alt=media&token=f1fda03a-6259-44d8-9bfc-013db5668695
Taken Down
IP: 142.251.38.106
Type: malware_download
First Seen: 2026-03-17
ascii base64-loader Encoded Formbook
https://firebasestorage.googleapis.com/v0/b/rodriakd-8413d.appspot.com/o/SV%2FPrince%20Denrik.txt?alt=media&token=a161f2b0-9ad8-4d6e-a621-ea9f4a944d6a
Taken Down
IP: 142.251.38.106
Type: malware_download
First Seen: 2026-03-17
ascii Formbook rev-base64-loader
https://firebasestorage.googleapis.com/v0/b/mis-archivos-2026-4b0c7.firebasestorage.app/o/tumfuf.txt?alt=media&token=1fcca767-bf37-4570-9a19-e24cdf9ba210
Active Threat
IP: 142.251.38.106
Type: malware_download
First Seen: 2026-03-17
ascii Formbook rev-base64-loader
https://firebasestorage.googleapis.com/v0/b/anyaa-7c774.firebasestorage.app/o/wowow1.png?alt=media&token=69f4a496-8bf1-4a7c-b3e5-d6cbb4040a0a
Active Threat
IP: 209.85.203.95
Type: malware_download
First Seen: 2026-03-02
None
Showing 20 of 90 URLs