connect-uphold-login-account[.]blogspot[.]li
“How Can You Safely Access Your Uphold Login Account?”
connect-uphold-login-account.blogspot.li — Непроверенный. Олицетворение бренда: Uphold; Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLScan malicious verdict; PhishDestroy score 89/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, connect-uphold-login-account.blogspot.li, is actively flagged as a high-risk credential phishing site targeting Uphold login credentials. Analysis indicates the domain resolves to 142.250.80.65 (AS15169, Google LLC, US-based infrastructure), suggesting the use of a legitimate hosting provider to evade initial reputation-based blocking. The page title, 'How Can You Safely Access Your Uphold Login Account?', explicitly confirms the impersonation of Uphold, a known digital money platform, aligning with the credential phishing classification. Technical indicators include an HTTP 302 redirect status, which may be leveraged to obscure the final malicious destination or bypass automated detection. The domain is hosted on Blogger, a platform frequently abused for low-cost phishing campaigns due to its free SSL certificates (issued by Google Trust Services / WE2) and ease of deployment. Detected technologies include Java, Python, and OpenGSE, though their specific roles in the phishing kit remain unconfirmed without deeper analysis. The domain appears on one security blocklist and is currently blocked by at least one vendor, though its active status as of July 12, 2026, indicates ongoing malicious activity. Defenders should prioritize blocking this domain at the DNS or proxy level, particularly in environments where Uphold credentials are used. The SSL certificate, while issued by a trusted provider, should not be treated as a trust indicator due to the domain's confirmed malicious intent. Given the use of Google-hosted infrastructure, monitoring for similar patterns (e.g., Blogger subdomains with financial service keywords) may help preemptively identify related threats. No evidence of widespread detection exists (11/95 vendors on VirusTotal), suggesting the campaign may still be in an early or targeted phase. Further investigation into the redirect chain and backend infrastructure is recommended to determine the full scope of the phishing operation.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 5 identified
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание