portal-uphold-en-auths[.]created[.]app
“Uphold Login | Secure Access to Your Uphold Account”
portal-uphold-en-auths.created.app — Прикритий · доступний. Уособлення бренду: Uphold; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 1 detections (engine total unavailable) (Webroot); URLQuery 1 alert; URLScan malicious verdict; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 66/100. Реєстратор: Tucows Domains.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, portal-uphold-en-auths.created.app, has been assessed with an elevated risk level due to its classification as a generic phishing site specifically designed to mimic the Uphold login page. PhishDestroy identified this threat through analysis of its page title, which explicitly reads 'Uphold Login | Secure Access to Your Uphold Account,' and its status as a confirmed phishing domain. The site is now offline, but its previous activity posed a direct risk to Uphold users seeking secure access to their accounts.
Technical indicators provide a clear picture of the threat. VirusTotal flagged the domain with 1 out of 95 security vendors marking it as malicious, and it appears on three security blocklists. The domain resolves to IP address 216.150.1.129 and was registered through Tucows Domains Inc. Its SSL certificate was issued by Let's Encrypt (R13), a common choice for fraudulent sites seeking to appear legitimate. The combination of these factors underscores the domain's intent to deceive users into entering sensitive credentials.
For those who may have interacted with this phishing site, immediate action is critical. Users should change their Uphold passwords and enable two-factor authentication if not already active. It is also advisable to monitor account statements for unauthorized transactions and report any suspicious activity to Uphold's support team. Additionally, running a security scan on any device that accessed the site can help detect potential malware or keyloggers. PhishDestroy recommends staying vigilant against similar phishing attempts by verifying URLs before entering credentials.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | portal-uphold-en-auths.created.app |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: created.app
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain created.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 9 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100% впевненостіReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% впевненостіVercel is a cloud platform for static frontends and serverless functions.
vercel.com 100% впевненостіNext.js is a React framework for developing single page Javascript applications.
nextjs.org 100% впевненостіLaunchDarkly is a continuous delivery and feature flags as a service platform that integrates into a company's current development cycle.
launchdarkly.com 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіCloud CDN uses Google's global edge network to serve content closer to users.
cloud.google.com 100% впевненостіАналіз VirusTotal
Докази та зовнішні звіти
PD-20260521-BB79EC Recipient: abuse@vercel.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога