uphold-logiinnn[.]blogspot[.]hr
“Det gick inte att hitta bloggen”
uphold-logiinnn.blogspot.hr — 未验证. 证据摘要: VirusTotal 11/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); PhishDestroy score 88/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, uphold-logiinnn.blogspot.hr, is currently listed as an active generic phishing infrastructure. The site returns an HTTP 302 redirect and presents the page title “Det gick inte att hitta bloggen”. It appears on one security blocklist and has been flagged by 14 of 95 VirusTotal scanners, indicating a high confidence of malicious intent. Network analysis shows the domain resolves to IP 142.250.186.65, which belongs to Google LLC and is geolocated in Germany. The host is served over TLS with a certificate issued by Google Trust Services under the WE2 designation, confirming the use of legitimate‑looking encryption. Detected web technologies include Blogger, Java, Python, OpenGSE, and support for HTTP/3. The combination of a redirect response, the presence of a generic “blog not found” title, and the association with known phishing blocklists suggests the site is being leveraged to host malicious URLs or to redirect victims to credential‑harvesting pages. The exact payload or credential‑capture mechanism has not been publicly disclosed, and the internal page content remains unverified. Given the high risk rating and the active status, defenders should ensure that network filtering solutions block resolve attempts to uphold‑logiinnn.blogspot.hr and any associated IP address. Continuous monitoring of DNS queries and TLS certificate fingerprints is recommended, as well as updating intrusion‑prevention signatures to reflect the observed redirection pattern. Incident response teams should treat any traffic to this domain as malicious and investigate potential compromise of affected users.
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 5 identified
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。