uphld-en-us[.]created[.]app
“Uphold Login - Secure Digital Asset Trading Platform | Invest in 200+ Assets”
uphld-en-us.created.app — Terselubung · dapat dijangkau. Peniruan identitas merek: Uphold; Jenis penipuan: Fake Exchange. Ringkasan bukti: VirusTotal 5/91 (Emsisoft, Fortinet, Google Safebrowsing, Netcraft, Webroot); URLScan malicious verdict; Google Safe Browsing flagged; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 80/100. Registrar: Name.com.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
The domain uphld-en-us.created.app is currently offline but exhibits multiple indicators of a high‑risk phishing operation targeting users of a digital‑asset trading platform. The site served a page titled "Uphold Login - Secure Digital Asset Trading Platform | Invest in 200+ Assets," directly impersonating the legitimate Uphold service, and the SSL certificate presented is from Let’s Encrypt (R13), a common choice for malicious actors due to its free issuance and rapid renewal. Infrastructure analysis shows the domain resolves to IP 216.150.1.129, hosted within Amazon’s AS16509 network in the United States, and uses Vercel DNS nameservers (ns1.vercel-dns.com, ns2.vercel-dns.com). The HTTP response is a 404 status, indicating the content has been removed or the host is no longer serving the page, consistent with the reported offline status.
Reputation checks reveal a Gridinsoft trust score of 0 / 100, Google Safe Browsing flags for social engineering, and five of ninety‑one VirusTotal scanners have flagged the domain as malicious. The domain appears on three security blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL, reinforcing its classification as a fake exchange phishing site. Registration details list Name.com, Inc. as the registrar, but no further registration metadata is available.
While the site is no longer reachable, the observed indicators suggest a previously active credential‑harvesting campaign. Defenders should continue to block the domain at network perimeters, update URL filtering and threat intelligence feeds with the IP address 216.150.1.129, and monitor for any re‑use of the associated infrastructure. Analysts should also audit logs for any attempted connections to this domain or its IP, and enforce multi‑factor authentication for accounts related to the Uphold brand to mitigate potential credential compromise.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Registration: created.app
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain created.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisis VirusTotal
Bukti & Laporan Eksternal
PD-20260623-32FA55 Recipient: abuse@vercel.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive