uphold-login-accountt[.]blogspot[.]sk
“Uphold Login Account | Secure Access”
uphold-login-accountt.blogspot.sk — Неперевірений. Уособлення бренду: Uphold; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 11/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, ESET); URLScan malicious verdict; PhishDestroy score 83/100. Реєстратор: MarkMonitor.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain is flagged as a credential‑phishing site targeting users of the Uphold service. The page title “Uphold Login Account | Secure Access” indicates an attempt to lure victims into entering credentials. Technical analysis shows the domain resolve to the IPv6 address 2a00:1450:4001:81c::2001, which belongs to the AS15169 Google network located in Germany. Registration was performed through MarkMonitor, Inc., and the authoritative nameservers are ns1‑ns4.google.com, confirming the use of Google’s DNS infrastructure. The site is hosted on Blogger and serves content over HTTP/3; additional runtimes detected include Java, Python and OpenGSE. An HTTP 302 redirect is observed, and the TLS certificate is issued by Google Trust Services (WE2), further confirming the underlying platform. The domain was created on 30 Nov 2006 and remains active as of the report date. It is listed on at least one public blocklist and has been blocked by PhishDestroy. VirusTotal scans show 11 of 95 security engines flag the domain, indicating a moderate consensus of malicious behavior. No additional payload or script analysis is available, so the exact phishing page content cannot be confirmed. Defenders should treat uphold-login-accountt.blogspot.sk as hostile. Network‑level controls should block traffic to the domain and its resolved IPv6 address. Email gateways should flag messages containing this URL, and endpoint protection should monitor for credential‑theft attempts associated with the Uphold brand. Continuous monitoring of the domain’s DNS records and any changes in hosting or certificate details is recommended to detect possible relocation of the phishing infrastructure.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 5 identified
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога