upholldtllooginn[.]godaddysites[.]com
“Uphōld Lōgin – Official Site”
upholldtllooginn.godaddysites.com — لم يتم التحقق منها. نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 14/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, ESET); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 100/100. مسجّل النطاق: GoDaddy.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
PhishDestroy identifies upholldtllooginn.godaddysites.com as an active crypto drainer domain designed to trick visitors into connecting cryptocurrency wallets and signing malicious transactions that silently drain funds. The site masquerades as a legitimate wallet login page to deceive users into authorizing on-chain transactions that transfer tokens to attacker-controlled addresses. Even a single click can expose your wallet address and lead to unauthorized transfers if fraudulent transaction signatures are approved. This domain was flagged by PhishDestroy’s automated pipeline using seed 66cf36, with initial detection occurring prior to November 18, 2013—its registration date via GoDaddy.com, LLC. The infrastructure is hosted behind IP 13.248.243.5 and secured with a GoDaddy SSL certificate, which is commonly abused to lend false legitimacy to phishing and drainer sites. As of the latest VirusTotal scan, 16 out of 95 security engines detected the domain, indicating it has not yet been widely blacklisted despite clear malicious intent. The long-standing registration and use of a reputable registrar and SSL provider highlight the sophisticated infrastructure often leveraged by financially motivated threat actors. If you visited upholldtllooginn.godaddysites.com, immediately disconnect your device from the internet to prevent further communication with the attacker’s server. Disconnect your cryptocurrency wallet and revoke any unauthorized transaction signatures using tools like WalletConnect or blockchain explorers that support signature revocation. Monitor your wallet for suspicious outgoing transfers and consider moving remaining assets to a new wallet with a fresh address. Report the domain to your wallet provider, the hosting platform (GoDaddy Sites), and relevant blockchain incident response platforms. Change passwords only if you entered any on the site, and consider using a hardware wallet with transaction simulation to prevent future attacks.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
Registration: godaddysites.com
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain godaddysites.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب