MALICIOUS — CRITICAL
uppholdlogin[.]gitbook[.]io
The domain uppholdlogin.gitbook.io is active and was registered on February 21, 2026.
- VirusTotal
- 13/91
- Blocklists
- No stored match
- Ketersediaan
- Terakhir diketahui aktif · HTTP 307
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
uppholdlogin.gitbook.io — Terakhir diketahui aktif (HTTP 307). Jenis penipuan: Credential Phishing. Ringkasan bukti: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, ESET, Fortinet); URLQuery 4 alerts; Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 99/100. Registrar: Cloudflare.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Evidence Analysis
uppholdlogin.gitbook.io Fake Uphold Login
The domain uppholdlogin.gitbook.io is active and was registered on February 21, 2026.
The domain uppholdlogin.gitbook.io is active and was registered on February 21, 2026. DNS resolution points to IP address 172.64.147.209, which belongs to Cloudflare, Inc. (AS13335) and is located in the United States. The domain is hosted on the GitBook platform and uses Cloudflare's DNS service (nameservers dahlia.ns.cloudflare.com and hugh.ns.cloudflare.com) with HSTS, Google Cloud Trace, and HTTP/3 enabled. An SSL certificate issued by Google Trust Services under the WE1 label secures the site. HTTP requests receive a 307 temporary redirect response, suggesting a possible URL forwarding step in the phishing flow. Google Safe Browsing classifies the site under the SOCIAL_ENGINEERING category, and 19 of 95 security vendors on VirusTotal have flagged it as malicious. The domain appears on one public blocklist and is actively blocked by PhishDestroy. The page title observed is "Ûphold Loℊin | Sign In 💎", indicating an attempt to impersonate the Uphold login portal. While the exact content of the landing page has not been analyzed, the technical indicators collectively point to a credential‑phishing infrastructure targeting Uphold users. Defenders should block DNS resolution for uppholdlogin.gitbook.io, add the domain to web filtering and email security policies, and monitor for any authentication attempts to Uphold accounts originating from this host. Continuous threat‑intel feeds should be consulted for any updates on related indicators of compromise.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Cakupan data12 recorded checks
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | uppholdlogin.gitbook.io |
malicious | Sinkholed |
| OpenDNS | uppholdlogin.gitbook.io |
phishing | Phishing Block |
| DigiCert UltraDNS | uppholdlogin.gitbook.io |
malicious | Sinkholed |
| DNS4EU | uppholdlogin.gitbook.io |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Teknologi · 6 identified
Suite of cloud computing services running on Google infrastructure.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of uppholdlogin.gitbook.io · checked Mar 2, 2026
Bukti & Laporan EksternalIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.