docs-uphold-wallet[.]blogspot[.]lu
“Blog not found”
docs-uphold-wallet.blogspot.lu — Não verificado. Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 12/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); CF Radar malicious; PhishDestroy score 86/100. Registrador: MarkMonitor.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of the domain docs-uphold-wallet.blogspot.lu confirms its classification as an active crypto drainer phishing site, targeting cryptocurrency wallet users. Registered on February 21, 2026, through MarkMonitor, Inc., the domain currently resolves to IP address 172.217.20.129, hosted on Google LLC infrastructure (AS15169) in the United States. The site returns an HTTP 302 redirect status, though the destination remains unconfirmed, and displays a 'Blog not found' page title, suggesting either a placeholder or obfuscated landing page. Security vendor detections are present but limited: seven of 95 engines on VirusTotal flagged the domain as malicious at the time of assessment.
The domain appears on three security blocklists, including PhishDestroy, MetaMask, and SEAL, which specifically categorize it as a crypto scam. Infrastructure analysis reveals the use of Blogger as the hosting platform, alongside backend technologies such as Java, Python, OpenGSE, and HTTP/3. The SSL certificate is issued by Google Trust Services (WE2), consistent with standard Blogger deployments but offering no inherent trust beyond the issuing authority. The exact content and functionality of the site remain unanalyzed, as no direct observation of phishing forms, wallet-draining scripts, or brand impersonation has been documented.
However, the combination of detection by crypto-focused security tools, blocklist inclusion, and the domain's naming convention—suggesting an association with Uphold wallet—supports its classification as a high-risk crypto drainer. Defenders should treat this domain as actively malicious, block access at the network and endpoint levels, and monitor for related infrastructure, particularly subdomains or redirects that may facilitate wallet credential theft or unauthorized transactions. Further investigation into associated IP ranges and certificate reuse is recommended to identify linked phishing campaigns.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 5 identified
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo