Is app-uphlood.zapier.app safe?
http://app-uphlood.zapier.app/
Phishing site impersonating Uphold at app-uphlood.zapier.app [observed:safe-browsing][source:antivirus:aggregate]
The page at https://app-uphlood.zapier.app/ displays a fake Uphold crypto login portal with official branding, a QR code, and login prompts. Multiple engines flag it as phishing/social engineering; it is not operated by Uphold. [observed:safe-browsing][observed:virustotal]
Read the full analysisLoading saved screenshot
Preparing the saved page preview.
01 · Investigation Brief
Investigation Brief
The page at https://app-uphlood.zapier.app/ displays a fake Uphold crypto login portal with official branding, a QR code, and login prompts. Multiple engines flag it as phishing/social engineering; it is not operated by Uphold. [observed:safe-browsing][observed:virustotal]
What the site appears to do
Mimics Uphold's login page with heading 'Log In® Uphold® | Sign In' and promotional text about trading tools and multi-currency management. Includes a Zapier 'Built on' link and Report button. No actual login form fields visible in the captured content. [observed:page-block:document:primary:block:1][observed:page-block:document:primary:block:2]
Strongest evidence and limitations
Google Safe Browsing and 7 VirusTotal engines (alphaMountain.ai, Emsisoft, Forcepoint, Fortinet, Netcraft, Webroot) detect phishing. Domain created 2022 but uses misspelled 'uphlood' subdomain on Zapier hosting. No credential fields captured and no downloads observed. [observed:safe-browsing][observed:virustotal][observed:domain-age]
Practical user impact
Visiting risks credential theft if users enter Uphold login details. Avoid entering any information. Use official Uphold app or uphold.com directly. The Zapier-hosted page can be reported via the on-page button. [observed:safe-browsing]
Why the score is 8
7 independent antivirus familyies reported an adverse result. Coverage remains separate so missing sources cannot be mistaken for clean results.
02 · Security Evidence
Security evidence
Antivirus Engines
Fresh result
7 engines flagged this URL
Every saved adverse engine is listed below. The full provider matrix remains available for audit.
- Malicious
- 7
- Suspicious
- 0
- Total
- 92
| Engine | Finding |
|---|---|
| alphaMountain.aiMalicious | phishing |
| EmsisoftMalicious | phishing |
| Forcepoint ThreatSeekerMalicious | phishing |
| FortinetMalicious | phishing |
| Google Safe BrowsingMalicious | phishing |
| NetcraftMalicious | malicious |
| WebrootMalicious | malicious |
All 92 engine results
- alphaMountain.ai - phishing - Malicious
- Emsisoft - phishing - Malicious
- Forcepoint ThreatSeeker - phishing - Malicious
- Fortinet - phishing - Malicious
- Google Safe Browsing - phishing - Malicious
- Netcraft - malicious - Malicious
- Webroot - malicious - Malicious
- 0xSI_f33d - unrated - Clean
- Abusix - clean - Clean
- Acronis - clean - Clean
- ADMINUSLabs - clean - Clean
- AILabs (MONITORAPP) - clean - Clean
- AlienVault - clean - Clean
- AlphaSOC - unrated - Clean
- Antiy-AVL - clean - Clean
- ArcSight Threat Intelligence - unrated - Clean
- AutoShun - unrated - Clean
- Bfore.Ai PreCrime - unrated - Clean
- BitDefender - clean - Clean
- Bkav - unrated - Clean
- BlockList - clean - Clean
- Blueliv - clean - Clean
- Certego - clean - Clean
- ChainPatrol - clean - Clean
- Chong Lua Dao - unrated - Clean
- CINS Army - clean - Clean
- Cluster25 - unrated - Clean
- CRDF - clean - Clean
- Criminal IP - unrated - Clean
- CSIS Security Group - unrated - Clean
- CTX AI - clean - Clean
- Cyan - unrated - Clean
- Cyble - clean - Clean
- CyRadar - clean - Clean
- desenmascara.me - clean - Clean
- DNS8 - unrated - Clean
- Dr.Web - clean - Clean
- EmergingThreats - clean - Clean
- Ermes - unrated - Clean
- ESET - clean - Clean
- ESTsecurity - clean - Clean
- Fortra - unrated - Clean
- G-Data - clean - Clean
- GCP Abuse Intelligence - unrated - Clean
- GreenSnow - clean - Clean
- GreyNoise - unrated - Clean
- Gridinsoft - unrated - Clean
- Guardpot - unrated - Clean
- Heimdal Security - clean - Clean
- Hunt.io Intelligence - unrated - Clean
- IPsum - clean - Clean
- Juniper Networks - clean - Clean
- K7AntiVirus - unrated - Clean
- Kaspersky - clean - Clean
- LevelBlue - clean - Clean
- Lionic - clean - Clean
- Lumu - unrated - Clean
- Malwared - clean - Clean
- MalwarePatrol - clean - Clean
- MalwareURL - unrated - Clean
- Mimecast - unrated - Clean
- OpenPhish - clean - Clean
- PhishFort - unrated - Clean
- Phishing Database - clean - Clean
- Phishtank - clean - Clean
- PREBYTES - clean - Clean
- PrecisionSec - unrated - Clean
- Quick Heal - clean - Clean
- Quttera - clean - Clean
- Rising - clean - Clean
- SafeToOpen - unrated - Clean
- Sangfor - clean - Clean
- Sansec eComscan - unrated - Clean
- Scantitan - clean - Clean
- SCUMWARE.org - clean - Clean
- Seclookup - clean - Clean
- Snort IP sample list - unrated - Clean
- SOCRadar - unrated - Clean
- Sophos - clean - Clean
- StopForumSpam - clean - Clean
- Sucuri SiteCheck - clean - Clean
- ThreatHive - clean - Clean
- URLhaus - clean - Clean
- URLQuery - unrated - Clean
- Viettel Threat Intelligence - clean - Clean
- VIPRE - unrated - Clean
- ViriBack - clean - Clean
- VX Vault - clean - Clean
- Xcitium Verdict Cloud - clean - Clean
- Yandex Safebrowsing - clean - Clean
- ZeroCERT - clean - Clean
- ZeroFox - unrated - Clean
Security Scans
Detected threat categories: SOCIAL_ENGINEERING.
What we observed
Loading saved screenshot
Preparing the saved page preview.
Captured during this scan in a safe sandbox. Opening this report does not revisit the site. Marker positions are approximate. See full visual analysis →
Visual warning signs were identified
Uphold logo and 'Discover Crypto Better' headline present
What the captured page showed
1 observation- 01
Uphold logo and 'Discover Crypto Better' headline present
03 · Investigation Story
Investigation story
- 1
What the site claims
Log In® Uphold® | Sign In
- 2
What we observed
The page content was captured and checked alongside 92 antivirus results.
- 3
What independent research found
No complete independent-research result was available in this saved report.
- 4
What remains unverified
1 of the five core capabilities did not complete, so those gaps remain visible in the coverage ledger.
What kind of site and risk is this?
Threat category
Phishing & Impersonation
Also observed: Investment, Crypto & Wallet Fraud
Service and business model
Login Portal
Unknown
Observed behavior
Evidence behind this classification
- 017 independent antivirus familyies reported an adverse result.
Reputation Sources
How this domain rates across independent threat-intelligence and blocklist providers.
04 · Domain & Infrastructure
Domain & infrastructure
The plumbing behind the site — who registered it, how it’s encrypted, where it’s hosted, and where it links out. A valid certificate or a calm server doesn’t mean the business is honest — scam sites pass these checks too. Use this to corroborate the verdict, not to overturn it.
Infrastructure map
How the saved page connected to the wider web.
Domain Timeline
- Sep 20, 2022Domain registered
First appeared in WHOIS records — 3.9 years old today.
- Jul 31, 2026Saved security review — Flagged as dangerous
The completed checks from this saved scan are detailed above.
app-uphlood.zapier.app is an established domain now carrying threat signals. An older domain that starts tripping security checks is a classic pattern for an asset that was sold, repurposed, or compromised — the age alone is not reassurance.
Contact Verification
Saved contact details can help identify the operator. Their presence supports traceability; it does not prove the business is trustworthy.
- No direct contact email found on the captured page.
Domain & Encryption
Redirect Chain
- 1308http://app-uphlood.zapier.app/
- 2200https://app-uphlood.zapier.app/
Server Reputation
Referenced Domains
Outbound domains this page links to or loads resources from. Each links to its own security scan.
05 · Evidence Ledger
Evidence ledger
The conclusion is supported by the evidence saved with this report.
Technical threat
Malware, phishing, credential theft and hostile infrastructure.
Additional evidence review · Additional evidence review
Operator / customer risk
Complaints, withdrawals, business conduct and commercial traps.
No confirmed evidence in this dimension.
Source coverage and freshness
Status shows whether usable evidence was saved; finding shows what that evidence observed.
| Source | Result | Completion | Finding | Freshness |
|---|---|---|---|---|
| Antivirus | 7 of 92 engines flagged | Completed | Adverse | fresh · Jul 31, 2026 |
| Browser protection | 1 browser threat category matched | Completed | Adverse | Not available |
| Page content | Page fetched · HTTP 200 | Completed | No adverse finding | Not available |
| Visual evidence | 1 visible observation saved with the page capture | Completed | Adverse | Not available |
| Independent research | Independent research was not available for this report | Unavailable | No saved finding | Not available |
- Page content
- Result: Page fetched · HTTP 200
- Completed
- No adverse finding
- Visual evidence
- Result: 1 visible observation saved with the page capture
- Completed
- Adverse
- Independent research
- Result: Independent research was not available for this report
- Unavailable
- No saved finding
07 · Community
Community
08 · Safety FAQ
Safety FAQ
Common questions, answered directly from the scan data above — so the answers reflect the saved verdict and evidence in this report.

0 community contributions
Share what happened, what the site requested, and what others should watch for.
Community reviews never change the scanner verdict.