app-uphold-login[.]blogspot[.]hr
“Uphold Login | Secure Digital Access”
app-uphold-login.blogspot.hr — 확인되지 않음. 사기 유형: Credential Phishing. 증거 요약: VirusTotal 8/91 (alphaMountain.ai, BitDefender, CyRadar, ESET, Fortinet); PhishDestroy score 74/100.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
This domain is flagged for hosting a credential theft operation targeting users of the Uphold digital asset platform. Analysis indicates the site impersonates the legitimate Uphold login interface under the title 'Uphold Login | Secure Digital Access,' a tactic designed to deceive users into submitting their authentication credentials. The threat level is classified as elevated due to the domain's active deployment in a targeted phishing campaign and its detection by multiple security mechanisms. Infrastructure analysis reveals the domain resolves to the IP address 142.250.185.193, which is registered under AS15169 (Google LLC) and located in the United States. The SSL certificate is issued by Google Trust Services (WE2), a common characteristic of attacker-abused free hosting platforms. Detection metrics from VirusTotal show that 11 out of 95 security vendors have flagged the domain as malicious, while it appears on at least one security blocklist. The domain is currently offline, though its prior operational status and detection history warrant continued scrutiny. To mitigate risks associated with credential theft, affected users should immediately revoke any sessions linked to the fraudulent domain and enable multi-factor authentication on their legitimate accounts. Organizations should update endpoint protection rules to block the domain and its associated IP address (142.250.185.193) at the network perimeter. Security teams are advised to monitor for unauthorized access attempts originating from credentials potentially compromised through this campaign, particularly those tied to financial or cryptocurrency platforms. Users who interacted with the domain should assume their credentials were exposed and take proactive steps to secure their accounts.
위협 대응 Pipeline
공개 차단 목록 상태
사용 기술 · 5 identified
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 분석
보관된 증거
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.