sso-uphold-cloud[.]tem3[.]io
“Log In | Uphold® | Sign In to Your Account - uphold login”
sso-uphold-cloud.tem3.io — 未验证. 品牌冒充:Uphold; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 21/91 (ChainPatrol, BitDefender, Chong Lua Dao, Cluster25, CRDF); URLScan malicious verdict; PhishDestroy score 95/100. 注册商: GoDaddy.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain sso-uphold-cloud.tem3.io is a confirmed phishing site targeting users of the financial services platform Uphold. The domain is designed to mimic the legitimate log-in page of Uphold, potentially leading to credential theft and financial loss. No specific drainer kit has been identified in the analysis.
Technical indicators reveal that this domain has been flagged by 18 out of 95 security vendors on VirusTotal, indicating a significant level of suspicion among security experts. The domain is registered through GoDaddy.com, LLC and resolves to an IP address in the United States (104.21.79.46), which is part of the AS13335 Cloudflare, Inc. network. The domain was created on August 02, 2024, and the SSL certificate is issued by Google Trust Services / WE1. The site is currently listed on one security blocklist and is blocked by the PhishDestroy system.
The domain remains active as of the latest assessment, posing a high risk to unsuspecting users. Immediate response actions include avoiding the site, reporting it to Uphold, and ensuring that any credentials potentially compromised are changed. Users are advised to verify the URL of the legitimate Uphold site and to use multi-factor authentication to enhance account security. The presence of the domain on a security blocklist and its high VirusTotal score suggest that it is a credible threat, and further monitoring and potential blacklisting by additional security services are recommended.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。