uphold-loginaccount[.]blogspot[.]ca
“How Can You Securely Access Your Uphold Login Account?”
uphold-loginaccount.blogspot.ca — Непроверенный. Олицетворение бренда: Uphold; Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 11/91 (ADMINUSLabs, alphaMountain.ai, AutoShun, BitDefender, ESET); URLScan malicious verdict; PhishDestroy score 88/100. Регистратор: MarkMonitor.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, uphold-loginaccount.blogspot.ca, is actively hosting a credential phishing page targeting users of the Uphold platform. Analysis indicates the site is designed to harvest login credentials, as evidenced by its page title, 'How Can You Securely Access Your Uphold Login Account?', which explicitly references Uphold. The domain is hosted on Blogger infrastructure, resolving to IP 142.251.179.132 (AS15169, Google LLC, US), and employs a 302 HTTP redirect, a common technique to obscure the final phishing destination or evade detection. The domain was registered on October 18, 2006, through MarkMonitor, Inc., and is currently active. It is flagged by at least one security blocklist and has been identified as malicious by 9 of 95 security vendors in a recent scan. SSL certification is provided by Google Trust Services, and the domain uses Google nameservers (ns1-4.google.com). Detected technologies include Blogger, Java, Python, OpenGSE, and HTTP/3, consistent with legitimate Blogger-hosted pages but repurposed for malicious activity. Defenders should note that this domain leverages trusted infrastructure to bypass initial scrutiny, a tactic increasingly observed in phishing campaigns. The use of a subdomain under blogspot.ca may also exploit user trust in familiar platforms. While the exact content of the phishing page remains unanalyzed, the combination of the page title, scam type (credential phishing), and detection by multiple security vendors confirms its malicious intent. Network-level blocking of the domain and IP, as well as monitoring for related subdomains or redirects, is recommended. Users should be alerted to the presence of this threat, particularly if Uphold credentials are a known target within their environment.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 5 identified
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание