uphold-login-accountt[.]blogspot[.]hu
“Uphold Login Account | Secure Access”
uphold-login-accountt.blogspot.hu — 未验证. 品牌冒充:Uphold; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 11/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, ESET, Fortinet); URLScan malicious verdict; PhishDestroy score 88/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
uphold-login-accountt.blogspot.hu is currently active and hosts a credential phishing site as indicated by the page title “Uphold Login Account | Secure Access”. HTTP requests receive a 302 redirect, and the domain resolves to the IPv6 address 2a00:1450:4001:810::2001, which belongs to AS15169 Google LLC and is geolocated in Germany. The TLS certificate is issued by Google Trust Services under the WE2 label, confirming the use of Google’s certificate infrastructure. Service fingerprinting reveals the presence of Blogger, Java, Python, OpenGSE, and HTTP/3, consistent with a typical blog‑hosted phishing deployment. Twelve of ninety‑five VirusTotal scanners have flagged the domain, and it is listed on a single security blocklist, with PhishDestroy confirming the block. The infrastructure analysis shows no additional hosting or command‑and‑control components beyond the identified Google‑hosted endpoint. While the exact content of the login page has not been examined, the combination of the deceptive title, redirect behavior, and vendor detections strongly supports a credential‑phishing classification. Defenders should add the domain to network deny lists, monitor DNS queries for the IPv6 address, and consider sinkholing the host to disrupt traffic. End‑users should be warned that any request to this URL is malicious and must be avoided.
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 5 identified
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。