docs-uphold-wallet[.]blogspot[.]com[.]cy
“Blog not found”
docs-uphold-wallet.blogspot.com.cy — Não verificado. Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); CF Radar malicious; PhishDestroy score 89/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of the domain docs-uphold-wallet.blogspot.com.cy indicates active infrastructure linked to a crypto drainer scam, as classified by multiple security vendors. The domain was registered on February 21, 2026, and currently resolves to IP 142.251.140.161, hosted on Google LLC's AS15169 in the United States. The SSL certificate is issued by Google Trust Services (WE2), a common provider for both legitimate and malicious domains leveraging Blogger infrastructure. The HTTP response code is 302, suggesting a redirect mechanism, though the destination remains unconfirmed. The page title 'Blog not found' may indicate either a placeholder state or an attempt to evade detection by presenting minimal content.
Seven of 95 security vendors on VirusTotal have flagged this domain, with blocklist entries from PhishDestroy, MetaMask, and SEAL, all of which specialize in cryptocurrency-related threats. The domain appears on three additional security blocklists, reinforcing its classification as a high-risk crypto scam. Nameserver configuration includes cy-ns.anycast.pch.net, estia.ics.forth.gr, ns31.rcode0.net, and ns4.apnic.net, a mix of academic, research, and commercial providers that may complicate takedown efforts. Detected technologies include Blogger, Java, Python, OpenGSE, and HTTP/3, consistent with a hosted service environment rather than a dedicated malicious server. While the exact brand impersonation is not explicitly confirmed in the page title or provided intelligence, the domain name includes 'uphold-wallet,' strongly suggesting an attempt to mimic Uphold, a cryptocurrency wallet and exchange platform.
The scam type is explicitly labeled as a crypto scam, and the presence of MetaMask and SEAL blocks further supports the crypto drainer classification. Defenders should treat this domain as active and high-risk, prioritizing blocking at the DNS and network levels. Given the use of Blogger infrastructure, monitoring for similar patterns (e.g.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 5 identified
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo