uphold-login-en[.]blogspot[.]com[.]eg
“Uphold Login - Secure Access to Your Financial Accounts”
uphold-login-en.blogspot.com.eg — No verificado. Suplantación de marca: Uphold; Tipo de estafa: Credential Phishing. Resumen de las pruebas: VirusTotal 12/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, ESET); URLScan malicious verdict; PhishDestroy score 86/100.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain uphold-login-en.blogspot.com.eg is currently active and has been classified as a credential phishing site targeting users of the Uphold financial service. The site presents the page title “Uphold Login - Secure Access to Your Financial Accounts,” which aligns with the observed scam type. Analysis shows the domain resolves to the IPv6 address 2a00:1450:4001:828::2001 and returns an HTTP 302 status code, indicating a redirection mechanism typical of phishing infrastructure.
The underlying infrastructure is hosted by Google LLC, as indicated by the IP location in Germany (DE) and ASN 15169. The SSL certificate is issued by Google Trust Services under the WE2 designation, confirming the use of legitimate TLS certificates to lend credibility. Detected technologies include Blogger, Java, Python, OpenGSE, and HTTP/3, suggesting the site leverages common web‑application platforms rather than a specialized phishing kit.
Reputation data shows the domain is listed on a single security blocklist and has been blocked by the PhishDestroy mitigation system. VirusTotal scans have flagged the domain by 14 out of 95 security vendors, reflecting a moderate level of consensus regarding its malicious nature. The presence of only one public blocklist entry may indicate limited exposure or recent deployment, while the vendor detections provide corroborating evidence of phishing activity.
Defenders should add the IPv6 address 2a00:1450:4001:828::2001 and the fully qualified domain name to their deny lists and monitor DNS queries for similar subdomains under the blogspot.com.eg hierarchy. Because the site uses a valid TLS certificate, network‑level TLS inspection or certificate pinning can help differentiate legitimate Google services from this malicious actor. Continuous re‑evaluation of blocklist status and periodic VirusTotal rescans are recommended to track changes in vendor detection rates.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 5 identified
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Evidencias archivadas
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.