pop-upheld[.]pages[.]dev
فحص التصيد والأمان للنطاق pop-upheld.pages.dev
“Uphold Login™ | Secure Sign-In Guide ⚡”
pop-upheld.pages.dev — يمكن الوصول إليها · الوصول مقيد (HTTP 403). نوع الاحتيال: Credential Phishing. ملخص الأدلة: VirusTotal 12 detections (engine total unavailable) (BitDefender, CyRadar, ESET, Emsisoft, Fortinet); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 86/100. مسجّل النطاق: Cloudflare.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of the domain pop-upheld.pages.dev indicates it was a credential-phishing site targeting Uphold users, now offline as of July 23, 2026. The page title, 'Uphold Login™ | Secure Sign-In Guide ⚡,' explicitly suggests an attempt to mimic the legitimate Uphold login interface, though no direct visual confirmation of the site’s content is available. The domain was flagged by Google Safe Browsing for social engineering and appears on at least one security blocklist. Twelve out of 95 security vendors on VirusTotal detected the domain as malicious, reinforcing its classification as a high-risk threat. Infrastructure analysis reveals the domain was hosted on Cloudflare’s network (AS13335) at IP address 172.66.45.44, located in the United States.
It was registered through Cloudflare on February 21, 2026, and used Cloudflare nameservers (zainab.ns.cloudflare.com and rex.ns.cloudflare.com). The SSL certificate was issued by Google Trust Services (WE1), a common practice for both legitimate and malicious sites leveraging Cloudflare’s services. The site employed HTTP/3 and HSTS, technologies that do not inherently indicate malicious intent but are frequently used to lend an appearance of legitimacy. At the time of reporting, the domain returned an HTTP 403 status, indicating access was restricted or the site had been taken down.
Gridinsoft assigned a trust score of 0/100, further supporting its classification as malicious. While the exact phishing kit or post-compromise behavior remains unconfirmed, the available evidence—including the page title, detection by multiple security vendors, and Safe Browsing flags—strongly suggests this was a credential-harvesting operation. Defenders should treat any credentials potentially entered on this domain as compromised and monitor for related follow-up attacks, such as account takeovers or financial fraud.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
الاستخبارات الجنائية الرقمية
التقنيات · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org ثقة 100٪Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of pop-upheld.pages.dev · checked Apr 21, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب