connect-uphold-login-account[.]blogspot[.]li
“How Can You Safely Access Your Uphold Login Account?”
connect-uphold-login-account.blogspot.li — Nicht bestätigt. Markenidentität: Uphold; Betrugstyp: Credential Phishing. Zusammenfassung der Beweislage: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLScan malicious verdict; PhishDestroy score 89/100.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
This domain, connect-uphold-login-account.blogspot.li, is actively flagged as a high-risk credential phishing site targeting Uphold login credentials. Analysis indicates the domain resolves to 142.250.80.65 (AS15169, Google LLC, US-based infrastructure), suggesting the use of a legitimate hosting provider to evade initial reputation-based blocking. The page title, 'How Can You Safely Access Your Uphold Login Account?', explicitly confirms the impersonation of Uphold, a known digital money platform, aligning with the credential phishing classification. Technical indicators include an HTTP 302 redirect status, which may be leveraged to obscure the final malicious destination or bypass automated detection. The domain is hosted on Blogger, a platform frequently abused for low-cost phishing campaigns due to its free SSL certificates (issued by Google Trust Services / WE2) and ease of deployment. Detected technologies include Java, Python, and OpenGSE, though their specific roles in the phishing kit remain unconfirmed without deeper analysis. The domain appears on one security blocklist and is currently blocked by at least one vendor, though its active status as of July 12, 2026, indicates ongoing malicious activity. Defenders should prioritize blocking this domain at the DNS or proxy level, particularly in environments where Uphold credentials are used. The SSL certificate, while issued by a trusted provider, should not be treated as a trust indicator due to the domain's confirmed malicious intent. Given the use of Google-hosted infrastructure, monitoring for similar patterns (e.g., Blogger subdomains with financial service keywords) may help preemptively identify related threats. No evidence of widespread detection exists (11/95 vendors on VirusTotal), suggesting the campaign may still be in an early or targeted phase. Further investigation into the redirect chain and backend infrastructure is recommended to determine the full scope of the phishing operation.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 5 identified
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal-Analyse
Archivierte Beweise
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt