Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is network-abuse@google.com.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
uphold-logn-account[.]blogspot[.]in
“Uphold Login Account - Your Financial Control Center”
uphold-logn-account.blogspot.in — Non verificato. Tipo di truffa: Credential Phishing. Riepilogo delle prove: VirusTotal 7/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Fortinet, Lionic); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 75/100. Registrar: MarkMonitor.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
This domain was identified as a credential harvesting phishing site designed to mimic a legitimate financial services login portal. Visitors were presented with a fraudulent interface titled 'Uphold Login Account - Your Financial Control Center,' intended to deceive users into submitting sensitive account credentials, including usernames, passwords, and potentially multi-factor authentication codes. The site specifically targeted users of a well-known digital asset platform, exploiting trust in its branding to facilitate unauthorized access to financial accounts. Analysis indicates the domain was registered on February 21, 2026, through MarkMonitor, Inc., a registrar commonly associated with both legitimate and malicious domains. The site resolved to IP address 142.251.208.1, hosted under Google LLC (AS15169), which is consistent with the use of a free blogging platform to evade initial detection. Security vendor assessments on VirusTotal revealed that 10 out of 95 engines flagged the domain as malicious. Additionally, the domain appeared on three independent security blocklists, and its SSL certificate, issued by Google Trust Services, provided a superficial layer of legitimacy while failing to prevent classification as high-risk. Individuals who accessed this domain or entered credentials on the site should assume their login details have been compromised. Immediate steps include changing passwords for the targeted financial service and any other accounts where the same credentials may have been reused. Enabling multi-factor authentication, where available, is strongly recommended. Users should also monitor their financial accounts for unauthorized transactions and report any suspicious activity to the legitimate service provider. Organizations are advised to block the domain and associated IP at the network level to prevent further exposure.
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | uphold-logn-account.blogspot.com |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 5 identified
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisi di VirusTotal
Prove archiviate
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of uphold-logn-account.blogspot.in · checked Mar 2, 2026
Dati e relazioni esterne
PD-20260217-D44481 Recipient: network-abuse@google.com Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo