uphold-login-accountt[.]blogspot[.]ru
“Uphold Login Account | Secure Access”
uphold-login-accountt.blogspot.ru — Último activo conocido (HTTP 302). Suplantación de marca: Uphold; Tipo de estafa: Credential Phishing. Resumen de las pruebas: VirusTotal 12/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 96/100. Registrador: RU-CENTER-RU.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Uphold‑login‑accountt.blogspot.ru is flagged as a credential‑phishing site targeting users of the Uphold service. The site presents a page titled “Uphold Login Account | Secure Access”, indicating an attempt to harvest login credentials. Technical analysis shows the domain is hosted on Blogger infrastructure, as reflected by the presence of Google nameservers (ns1‑ns4.google.com) and an SSL certificate issued by Google Trust Services (WE2). The domain resolves to the IPv6 address 2a00:1450:4001:82a::2001, which belongs to the Google LLC network (AS15169) and is geolocated in Germany. HTTP requests receive a 302 redirect, a common technique for forwarding victims to a credential‑collection endpoint. The domain was created on 29 August 2005 and is registered through RU‑CENTER‑RU, suggesting an older registration that may be repurposed for malicious use.
VirusTotal scans have flagged the domain in 15 of 95 security engines, indicating a moderate consensus of malicious activity. The domain appears on at least one public blocklist and has been actively blocked by PhishDestroy, yet it remains reachable, confirming its active status. Detected technologies include Blogger, Java, Python, OpenGSE, and HTTP/3, consistent with a modern web stack that can support dynamic content and rapid content delivery. No further payload or script analysis is available, so the exact credential‑capture mechanism remains unknown.
Defenders should add the IPv6 address and the fully qualified domain name to web‑filtering and DNS‑sinkhole rules to prevent user access. Email gateways should inspect inbound messages for URLs pointing to the blogspot.ru domain and apply URL reputation checks. Because the site uses a legitimate Google‑issued TLS certificate, standard TLS inspection may be required to uncover malicious payloads. Continuous monitoring of the domain’s DNS records and blocklist status is advised, as the infrastructure can be altered without notice.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 5 identified
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Evidencias archivadas
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.