uphold-loginaccount[.]blogspot[.]ca
“How Can You Securely Access Your Uphold Login Account?”
uphold-loginaccount.blogspot.ca — Неперевірений. Уособлення бренду: Uphold; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 11/91 (ADMINUSLabs, alphaMountain.ai, AutoShun, BitDefender, ESET); URLScan malicious verdict; PhishDestroy score 88/100. Реєстратор: MarkMonitor.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, uphold-loginaccount.blogspot.ca, is actively hosting a credential phishing page targeting users of the Uphold platform. Analysis indicates the site is designed to harvest login credentials, as evidenced by its page title, 'How Can You Securely Access Your Uphold Login Account?', which explicitly references Uphold. The domain is hosted on Blogger infrastructure, resolving to IP 142.251.179.132 (AS15169, Google LLC, US), and employs a 302 HTTP redirect, a common technique to obscure the final phishing destination or evade detection. The domain was registered on October 18, 2006, through MarkMonitor, Inc., and is currently active. It is flagged by at least one security blocklist and has been identified as malicious by 9 of 95 security vendors in a recent scan. SSL certification is provided by Google Trust Services, and the domain uses Google nameservers (ns1-4.google.com). Detected technologies include Blogger, Java, Python, OpenGSE, and HTTP/3, consistent with legitimate Blogger-hosted pages but repurposed for malicious activity. Defenders should note that this domain leverages trusted infrastructure to bypass initial scrutiny, a tactic increasingly observed in phishing campaigns. The use of a subdomain under blogspot.ca may also exploit user trust in familiar platforms. While the exact content of the phishing page remains unanalyzed, the combination of the page title, scam type (credential phishing), and detection by multiple security vendors confirms its malicious intent. Network-level blocking of the domain and IP, as well as monitoring for related subdomains or redirects, is recommended. Users should be alerted to the presence of this threat, particularly if Uphold credentials are a known target within their environment.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 5 identified
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога