sendsushi[.]top
“Google”
Gespeicherte Erkennung
Cloaking-Warnung
- Cloaking-Typ
bot_redirect_safe- Cloaking-Wert
- 3/6
Zusammenfassung der Beweislage
The domain sendsushi.top was registered through Dynadot LLC on May 18, 2026 and is currently resolved to the Cloudflare address 188.114.97.3. It is served by the Cloudflare nameservers buck.ns.cloudflare.com and emily.ns.cloudflare.com, and presents a valid Let's Encrypt certificate identified as “E7”. HTTP requests receive a 302 redirect and the page title returned is “Google”, a common tactic used to obscure the malicious landing page.
Infrastructure analysis shows the hosting IP is located in Canada and is part of Cloudflare’s network, indicating the operator is leveraging a reputable CDN to hide the true origin of the site. The choice of a generic page title and the use of a legitimate SSL certificate suggest an attempt to gain user trust while impersonating the SushiSwap brand. No additional payload or script details are observable from the limited response, leaving the exact phishing technique (credential harvesting, wallet address substitution, etc.) uncertain.
The domain is listed on three security blocklists and has been flagged by the PhishDestroy, MetaMask, and SEAL blocklists. It appears in one AlienVault OTX pulse and has a Gridinsoft trust score of 0 out of 100. VirusTotal analysis reports a single security vendor flag out of ninety‑five, reinforcing the high‑risk classification assigned by analysts. The risk level is marked as high, and the status remains active as of the report date.
Defenders should proactively block the domain and its resolving IP at network perimeter devices and DNS filters. Monitoring for HTTP 302 redirects to the same IP and for newly issued Let's Encrypt certificates on Cloudflare‑hosted IPs can help detect similar campaigns. Incident response teams should be alert to potential credential or wallet address theft targeting SushiSwap users and advise affected users to verify URLs before entering sensitive information.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 10.08.2026
8 überwachte externe Feeds Kein Treffer
Domain-Intelligenz
Technische DetailsDNS, TLS-Namen und Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal-Analyse
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt