join-uphold[.]created[.]app
Phishing and security check for join-uphold.created.app
“Uphold Login* - Getting Started with Login”
Evidence Summary
join-uphold.created.app is a subdomain of created.app. PhishDestroy first observed the hostname on May 21, 2026. Stored content metadata identifies Google as the apparent target. Evidence score: 80/100 (critical).
7 independent sources recorded positive findings: VirusTotal, MetaMask, SEAL, Google Safe Browsing, Spamhaus DBL, and URLQuery, and others. VirusTotal stored 3 positive engine results: Google Safebrowsing, Kaspersky, Webroot; the total engine count is unavailable or inconsistent on Jul 18, 2026 at 18:45 UTC. MetaMask and SEAL listed the hostname in the separate external-blocklist snapshot on Aug 9, 2026 at 06:20 UTC. Google Safe Browsing flagged the domain: Social Engineering on Jun 26, 2026 at 03:04 UTC. Spamhaus DBL: DBL_PHISH on Jul 13, 2026 at 14:35 UTC.
Cloaking was recorded with HTTP 404 on Aug 9, 2026 at 01:03 UTC. The cloaking probe recorded status split conditional delivery at 1/100 on Aug 9, 2026 at 01:03 UTC: dead_http: raw=http_404; http=404; via=https_proxy; server=Vercel. Registration records for the registrable domain created.app list Tucows Domains Inc as the registrar and May 21, 2026 as the creation date. At collection time, the hostname resolved to 216.150.1.1 on AS16509 (Amazon.com, Inc.). The evidence archive retains 3 visual captures from PhishDestroy, URLScan, and URLQuery.
Data coverage12 recorded checks
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Registration: created.app
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For the registrable domain created.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 9 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100% confidenceReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% confidenceVercel is a cloud platform for static frontends and serverless functions.
vercel.com 100% confidenceNext.js is a React framework for developing single page Javascript applications.
nextjs.org 100% confidenceLaunchDarkly is a continuous delivery and feature flags as a service platform that integrates into a company's current development cycle.
launchdarkly.com 100% confidenceHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% confidenceCloud CDN uses Google's global edge network to serve content closer to users.
cloud.google.com 100% confidenceVirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of join-uphold.created.app · checked Jun 26, 2026
Evidence & External ReportsIndependent lookups and source reports
PD-20260521-BA9626 Recipient: abuse@vercel.com Victim safety and official reportingImmediate actions and verified reporting channels
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.