MALICIOUS — CRITICAL
Phishing- und Sicherheitsprüfung für spendsheep.today
spendsheep[.]
Analysis of spendsheep.today, registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, indicates active phishing infrastructure targeting PayPal users.
- VirusTotal
- 4/91
- Blocklists
- No stored match
- Verfügbarkeit
- Nicht bestätigt
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
spendsheep.today — Nicht bestätigt. Zusammenfassung der Beweislage: VirusTotal 4/91 (alphaMountain.ai, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); PhishDestroy score 76/100. Registrar: NiceNIC.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
Analysis of spendsheep.today, registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, indicates active phishing infrastructure targeting PayPal users. The domain resolves to 68.183.98.54, a US-based IP hosted by DigitalOcean, LLC, and is served by DigitalOcean nameservers. The page title 'Payram' suggests a likely attempt to mimic PayPal’s branding, though the exact content and functionality of the site remain unconfirmed as of this report. As of July 19, 2026, the domain returns an HTTP 200 status, confirming it is live and accessible. Four of 91 security vendors on VirusTotal have flagged the domain, and it appears in two AlienVault OTX threat intelligence pulses, reinforcing its malicious classification. The domain is also present on at least one security blocklist and is actively blocked by PhishDestroy. The SSL certificate is issued by Let’s Encrypt, which is commonly used by both legitimate and malicious sites. Defenders should treat this domain as high-risk, block it at the network level, and monitor for related indicators, including the associated IP and nameserver infrastructure. Further investigation into the site’s payload and targeting mechanisms is recommended, though no specific phishing kit or additional technical artifacts have been identified at this time.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Datenabdeckung12 recorded checks
Erkenntnisse zur Netzwerksicherheit Registrar context
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 02:54:16 UTC
Technologien · 6 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100 % KonfidenzReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100 % KonfidenzNginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100 % KonfidenzNext.js is a React framework for developing single page Javascript applications.
nextjs.org 100 % KonfidenzHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100 % KonfidenzVirusTotal-Analyse
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.