upholddesktop[.]net
“Uphold Desktop — Download the Uphold App for Windows”
upholddesktop.net — Conteúdo indisponível. Representação da marca: Uphold; Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 15/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); URLQuery 2 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. Registrador: Squarespace Domains.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain upholddesktop.net presents a significant risk of credential theft through targeted brand impersonation. The site actively mimics a legitimate digital asset platform, enticing users to download malicious software under the guise of a desktop application. This tactic is commonly used in credential theft campaigns, where unsuspecting individuals may inadvertently expose sensitive login information to threat actors. The risk remains under investigation as the site is still active and has not yet been widely flagged by automated security systems.
Technical analysis reveals several notable indicators. The domain upholddesktop.net is registered via Squarespace Domains LLC and resolves to IP address 91.92.241.250. The site was registered recently, on June 19, 2026, and is still online at the time of analysis. VirusTotal scans currently show 0 out of 95 engines detecting this domain as malicious, indicating it is not yet recognized by most threat intelligence platforms or blocklists. The page title, "Uphold Desktop — Download the Uphold App for Windows," demonstrates clear brand impersonation intent. No major external blocklists or trust score systems have yet flagged this domain, highlighting the importance of proactive detection.
To mitigate the threat posed by upholddesktop.net, users should avoid downloading or interacting with any applications or forms presented on the site. Security teams are advised to add this domain and its associated IP (91.92.241.250) to blocklists, monitor for related network traffic, and educate users on the risks of credential theft through brand impersonation. Enterprises should implement robust email and web filtering to prevent access to newly registered domains, especially those imitating established brands. Prompt reporting to relevant authorities and continued monitoring are strongly recommended until the domain is taken offline.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias · 2 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Evidências e relatórios externos
PD-20260702-FF4051 Recipient: abuse@omegatech.sc Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo