upholdloginn[.]created[.]app
Перевірка домену upholdloginn.created.app на фішинг і безпеку
“Uphold Login– Manage Crypto, Stocks & Money”
upholdloginn.created.app — Прикритий · доступний (HTTP 404). Уособлення бренду: Uphold. Зведення доказів: VirusTotal 10/91 (alphaMountain.ai, ESET, Emsisoft, Fortinet, Google Safebrowsing); URLScan malicious verdict; Spamhaus DBL_ABUSED_PHISH; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 80/100. Реєстратор: Name.com.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain is flagged as an active credential theft site specifically targeting cryptocurrency and financial account holders. Analysis indicates the infrastructure is designed to harvest login credentials for Uphold, a platform managing crypto, stocks, and fiat currencies. The threat type is classified as crypto credential theft, a subset of phishing that aims to gain unauthorized access to digital asset wallets and financial accounts for subsequent fund extraction or identity fraud.
Infrastructure analysis reveals the domain upholdloginn.created.app resolves to the IP address 216.150.1.193, with no prior detections on VirusTotal (0/95 engines). The page title mimics the legitimate Uphold platform, displaying 'Uphold Login– Manage Crypto, Stocks & Money,' a clear indicator of brand impersonation. The SSL certificate is issued by Let's Encrypt, a common tactic to lend superficial legitimacy to malicious sites. No blocklist entries or trust score downgrades were observed at the time of assessment, suggesting the campaign may still be in its early deployment phase or evading detection through low-volume targeting.
Mitigation steps for this specific threat type include immediate reporting to browser security teams, financial institutions, and domain registrars to initiate takedown procedures. Users who may have interacted with the domain should rotate credentials for all financial and crypto-related accounts, enable multi-factor authentication (MFA) where available, and monitor transaction histories for unauthorized activity. Organizations should update email and web filtering rules to block the domain and IP, and conduct internal awareness training to educate users on recognizing credential theft attempts targeting financial platforms. Indicators of compromise (IOCs) such as the domain, IP, and page title should be integrated into security monitoring tools for proactive detection.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: created.app
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain created.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 9 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100% впевненостіReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% впевненостіVercel is a cloud platform for static frontends and serverless functions.
vercel.com 100% впевненостіNext.js is a React framework for developing single page Javascript applications.
nextjs.org 100% впевненостіLaunchDarkly is a continuous delivery and feature flags as a service platform that integrates into a company's current development cycle.
launchdarkly.com 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіCloud CDN uses Google's global edge network to serve content closer to users.
cloud.google.com 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of upholdloginn.created.app · checked Jul 8, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога