app-uphold-login[.]blogspot[.]hr
“Uphold Login | Secure Digital Access”
app-uphold-login.blogspot.hr — Non vérifié. Type d'arnaque : Credential Phishing. Résumé des preuves: VirusTotal 8/91 (alphaMountain.ai, BitDefender, CyRadar, ESET, Fortinet); PhishDestroy score 74/100.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain is flagged for hosting a credential theft operation targeting users of the Uphold digital asset platform. Analysis indicates the site impersonates the legitimate Uphold login interface under the title 'Uphold Login | Secure Digital Access,' a tactic designed to deceive users into submitting their authentication credentials. The threat level is classified as elevated due to the domain's active deployment in a targeted phishing campaign and its detection by multiple security mechanisms. Infrastructure analysis reveals the domain resolves to the IP address 142.250.185.193, which is registered under AS15169 (Google LLC) and located in the United States. The SSL certificate is issued by Google Trust Services (WE2), a common characteristic of attacker-abused free hosting platforms. Detection metrics from VirusTotal show that 11 out of 95 security vendors have flagged the domain as malicious, while it appears on at least one security blocklist. The domain is currently offline, though its prior operational status and detection history warrant continued scrutiny. To mitigate risks associated with credential theft, affected users should immediately revoke any sessions linked to the fraudulent domain and enable multi-factor authentication on their legitimate accounts. Organizations should update endpoint protection rules to block the domain and its associated IP address (142.250.185.193) at the network perimeter. Security teams are advised to monitor for unauthorized access attempts originating from credentials potentially compromised through this campaign, particularly those tied to financial or cryptocurrency platforms. Users who interacted with the domain should assume their credentials were exposed and take proactive steps to secure their accounts.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 5 identified
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analyse VirusTotal
Preuves archivées
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif